AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2023-43622

HIGH · CVSS 7.5 EPSS 70.59%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2023-10-23 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 7.5. It affects Apache. Its EPSS score suggests a 70.6% probability of exploitation in the next 30 days.

CVE
CVE-2023-43622
Severity
HIGH
CVSS
7.5
EPSS
70.59%
Apache

Original NVD Description

An attacker, opening a HTTP/2 connection with an initial window size of 0, was able to block handling of that connection indefinitely in Apache HTTP Server. This could be used to exhaust worker resources in the server, similar to the well known "slow loris" attack pattern. This has been fixed in version 2.4.58, so that such connection are terminated properly after the configured connection timeout. This issue affects Apache HTTP Server: from 2.4.55 through 2.4.57. Users are recommended to upgrade to version 2.4.58, which fixes the issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)