CLEANSTART-2025-MG51423

See a problem?
Import Source
https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2025/CLEANSTART-2025-MG51423.json
JSON Data
https://api.osv.dev/v1/vulns/CLEANSTART-2025-MG51423
Upstream
Published
2026-10-01T07:10:27Z
Modified
2026-10-01T09:15:58Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023
Details

CVE-2023-44487 affects multiple packages. The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. See references for individual vulnerability details.

References

Affected packages

CleanStart / dotnet6-build

Package

Name
dotnet6-build

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
6.0.123-r0

Database specific

source
"https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2025/CLEANSTART-2025-MG51423.json"

CleanStart / dotnet6-runtime

Package

Name
dotnet6-runtime

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
6.0.23-r0

Database specific

source
"https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2025/CLEANSTART-2025-MG51423.json"