CVE-2023-44487
Patch Available.
This Vulnerability has been fixed in the Never-Ending Support (NES) version offered by HeroDevs.
Overview
Node.js is a JavaScript runtime built on Chrome's V8 JavaScript engine. It uses an event-driven, non-blocking I/O model and is widely used for web applications and server-side development. Node.js implements its http2 module, including http2.createServer() and http2.createSecureServer(), on top of nghttp2, a C library for the HTTP/2 protocol that Node.js bundles at deps/nghttp2 and compiles into the runtime.
A vulnerability (CVE-2023-44487), known as HTTP/2 Rapid Reset, has been identified in the HTTP/2 protocol and in the nghttp2 library bundled with Node.js. HTTP/2 lets a client cancel a request at any time by sending RST_STREAM. A client that opens a stream with a HEADERS frame and immediately resets it, over and over, can make a server start and abandon request processing far faster than any concurrent-stream limit would otherwise allow, exhausting the server's resources. The attack was exploited in the wild from August through October 2023.
This flaw maps to CWE-400 (Uncontrolled Resource Consumption), where software does not limit how much of a resource a request can make it use. HTTP/2's SETTINGS_MAX_CONCURRENT_STREAMS caps how many streams can be open at once, but a stream that has been reset no longer counts toward that cap even though the server may still be working on it. nghttp2 placed no bound on how quickly a client could reset streams, so the cap gave no protection against this pattern.
Every Node.js HTTP/2 server is exposed, whether created with http2.createServer() or http2.createSecureServer(), because the attack only needs a client to open a connection and send frames that the protocol allows. The Node.js project rated the issue High. Node.js HTTP/2 clients are not the target of this attack. This issue affects every Node.js release line that bundles nghttp2, from 8.4.0 through 20.x, up to the versions listed above.
Details
Module Info
- Product: Node.js
- Affected packages: node (bundles nghttp2 under deps/nghttp2)
- Affected versions: >=8.4.0 <=8.17.0 >=9.0.0 <=9.11.2 >=10.0.0 <=10.24.1 >=11.0.0 <=11.15.0 >=12.0.0 <=12.22.12 >=13.0.0 <=13.14.0 >=14.0.0 <=14.21.3 >=15.0.0 <=15.14.0 >=16.0.0 <=16.20.2 >=17.0.0 <=17.9.1 >=18.0.0 <18.18.2 >=19.0.0 <=19.9.0 >=20.0.0 <20.8.1
- GitHub repository: https://github.com/nodejs/node
- Published packages: https://nodejs.org/en/download
- Package manager: Not applicable; Node.js is distributed as runtime builds from nodejs.org rather than as a published npm package
- Fixed in: Node.js 18.18.2 and 20.8.1 (October 13, 2023), security releases that updated the bundled nghttp2 to 1.57.0; Node.js NES v16.20.3 (16.x line, shipped July 30, 2024), v14.21.4 (14.x line, shipped August 24, 2024) and v12.22.13 (12.x line, shipped November 10, 2025), none of which received an upstream fix. The other release lines listed above never received an updated nghttp2
Vulnerability Info
This High-severity vulnerability is found in nghttp2 before 1.57.0, the HTTP/2 library that Node.js bundles and statically links at deps/nghttp2, and in the HTTP/2 protocol design it implements. NVD assigns a CVSS v3.1 score of 7.5, and both nghttp2 and the Node.js project rate the issue High.
An HTTP/2 server allocates work for each new stream as soon as its HEADERS frame arrives, and when the client resets the stream, the server must clean that work up. Repeating the open-and-reset cycle at high speed keeps the server busy creating and tearing down streams while the concurrent-stream limit never triggers. The fix in nghttp2 1.57.0 adds a token-bucket rate limit on incoming RST_STREAM frames for servers, with a default burst of 1,000 and a refill rate of 33 per second; when a client exceeds it, nghttp2 sends GOAWAY and tears down the connection. See the nghttp2 fix commit and the nghttp2 advisory for details.
An unauthenticated remote attacker needs only network access to a Node.js HTTP/2 server. A small number of connections can generate enough open-and-reset cycles to drive CPU use up and starve legitimate requests, making the service unavailable for as long as the attack continues.
Note: Node.js applications that do not run an HTTP/2 server through the http2 module are not exposed by this issue. The http and https modules serve HTTP/1.1 and do not use nghttp2.
Mitigation
Users of the affected components should apply one of the following mitigations:
- Upgrade to a currently supported Node.js LTS release (22.x or 24.x), both of which bundle an nghttp2 version that includes this fix.
- Where an upgrade is not yet possible, terminate HTTP/2 at a patched reverse proxy or load balancer, or count RST_STREAM frames per session and close sessions that send them excessively, as the nghttp2 advisory suggests.
- Leverage a commercial support partner like HeroDevs for post-EOL security support, through Node.js NES.
Credits
- Reporter not named in the CVE record
- Tatsuhiro Tsujikawa from the nghttp2 project (remediation developer)
- James M Snell (updated the bundled nghttp2 in Node.js)