• Explore the unified API Platform
        • BUILD APIs
        • Kong Insomnia
        • API Design
        • API Mocking
        • API Testing & Debugging
        • MCP Client
        • RUN APIs
        • API Gateway
        • Context Mesh
        • AI Gateway
        • Event Gateway
        • Kubernetes Operator
        • Service Mesh
        • Ingress Controller
        • Runtime Management
        • DISCOVER APIs
        • Developer Portal
        • Service Catalog
        • MCP Registry
        • GOVERN APIs
        • Metering & Billing
        • APIOps & Automation
        • API Observability
        • Why Kong?
      • CLOUD
      • Cloud API Gateways
      • Need a self-hosted or hybrid option?
      • COMPARE
      • Considering AI Gateway alternatives?
      • Kong vs. Postman
      • Kong vs. MuleSoft
      • Kong vs. Apigee
      • Kong vs. IBM
      • GET STARTED
      • Sign Up for Kong Konnect
      • Documentation
  • Agents
      • FOR PLATFORM TEAMS
      • Developer Platform
      • Kubernetes & Microservices
      • Observability
      • Service Mesh Connectivity
      • Kafka Event Streaming
      • FOR EXECUTIVES
      • AI Connectivity
      • Open Banking
      • Legacy Migration
      • Platform Cost Reduction
      • Kafka Cost Optimization
      • API Monetization
      • AI Monetization
      • AI FinOps
      • FOR AI TEAMS
      • AI Cost Control
      • AI Governance
      • AI Integration
      • AI Security
      • Agentic Infrastructure
      • MCP Production
      • MCP Traffic Gateway
      • FOR DEVELOPERS
      • Mobile App API Development
      • GenAI App Development
      • API Gateway for Istio
      • Decentralized Load Balancing
      • BY INDUSTRY
      • Financial Services
      • Healthcare
      • Higher Education
      • Insurance
      • Manufacturing
      • Retail
      • Software & Technology
      • Transportation
      • See all Solutions
      • DOCUMENTATION
      • Kong Konnect
      • Kong Gateway
      • Kong Mesh
      • Kong AI Gateway
      • Kong Insomnia
      • Plugin Hub
      • EXPLORE
      • Blog
      • Learning Center
      • eBooks
      • Reports
      • Demos
      • Customer Stories
      • Videos
      • EVENTS
      • AI + API Summit
      • Webinars
      • User Calls
      • Workshops
      • Meetups
      • See All Events
      • FOR DEVELOPERS
      • Get Started
      • Community
      • Certification
      • Training
      • COMPANY
      • About Us
      • Why Kong?
      • We're Hiring!
      • Press Room
      • Investors
      • Contact Us
      • PARTNER
      • Kong Partner Program
      • SECURITY
      • Trust and Compliance
      • SUPPORT
      • Enterprise Support Portal
      • Professional Services
      • Documentation
      • Press Releases

        Kong Names Bruce Felt as Chief Financial Officer

        Read More
  • Pricing
  • Login
  • Get a Demo
  • Start for Free
Blog
  • AI Gateway
  • AI Security
  • AIOps
  • API Security
  • API Gateway
|
    • API Management
    • API Development
    • API Design
    • Automation
    • Service Mesh
    • Insomnia
    • View All Blogs
  1. Home
  2. Blog
  3. Product Releases
  4. Kong Releases Product Updates to Address Novel HTTP/2 'Rapid Reset' DDoS Vulnerability
Product Releases
October 12, 2023
2 min read

Kong Releases Product Updates to Address Novel HTTP/2 'Rapid Reset' DDoS Vulnerability

Tom Brightbill
Group Product Manager

At Kong, the security and reliability of our products have always been paramount. In light of the recent discovery of the Novel HTTP/2 ‘Rapid Reset’ DDoS attack (CVE-2023-44487), we have taken steps to proactively address potential issues. Today we’re providing guidance on how our users can best safeguard their systems. 

What is the HTTP/2 Rapid Reset Attack?

This vulnerability exploits the 'concurrent streaming' capability of HTTP/2. In this attack, a client can flood the server with a very high number of HTTP/2 stream requests that are immediately reset. This causes the server to spend a lot of resources cleaning up these canceled streams. These types of requests are legal in HTTP/2 and a malicious client can defeat existing flood prevention checks with minimal work.

The servers end up spending too much time in cleaning up the canceled streams, thus preventing them from servicing valid traffic, causing a Denial of Service.

We urge customers with HTTP/2-enabled servers to liaise with their web server providers to ensure timely application of essential patches.

Immediate Action Taken by Kong

All supported versions of Kong Gateway, Kong Mesh, and Kuma have been patched and released. The following versions contain a fix for the HTTP/2 rapid reset attack:

  • Kong Gateway Enterprise: 2.8.4.4, 3.1.1.6, 3.2.2.5, 3.3.1.1, 3.4.1.1
  • Kong Gateway OSS: 3.4.2
  • Kong Mesh: 2.0.8, 2.1.7, 2.2.5, 2.3.3, 2.4.3
  • Kuma: 2.0.8, 2.1.7, 2.2.5, 2.3.3, 2.4.3

For users using the Docker official image for Kong OSS, we have submitted an updated version and are waiting for the fix to be merged. To update immediately, please switch to the kong/kong image. For customers using Kong Enterprise images, the updates are available immediately. 

Mitigation Steps

If you cannot immediately update to the latest patches containing our fixes, we recommend the following mitigation steps:

  1. Disable HTTP/2 Support in Kong
  2. Reduce the HTTP/2 keepalive limit

You can find more information about the details of implementing these mitigation measures in the Kong knowledge base.

At Kong, we appreciate the trust you place in us and in our products. We are committed to ensuring the security of our community and will continue to monitor and address vulnerabilities proactively. Lastly, we highly recommend that all of our users evaluate their systems, apply the necessary patches, and follow the mitigation steps provided.

API SecurityAPI Gateway

More on this topic

Webinars

Quarterly Platform Updates & Roadmap Webinar

Demos

How Should API Gateways And Service Mesh Fit Into Your API Platform?

See Kong in action

Accelerate deployments, reduce vulnerabilities, and gain real-time visibility. 

Get a Demo
Topics
API SecurityAPI Gateway
Tom Brightbill
Group Product Manager

Recommended posts

Kong Event Gateway: Unifying APIs and Events in a Single API Platform

Product ReleasesMay 13, 2025

Kong customers include some of the most forward-thinking, tech-savvy organizations in the world. And while we’re proud to help them innovate through traditional APIs, the reality is that their ambitions don’t stop there. Increasingly, our customers a

Umair Waheed

Kong Gateway 3.9: Extended AI Support and Enhanced Security

Product ReleasesDecember 20, 2024

Today we're excited to announce Kong Gateway 3.9!  Since unveiling Kong Gateway 3.8 at API Summit 2024 just a few months ago, we’ve been busy making important updates and improvements to Kong Gateway. This release introduces new functionality arou

Alex Drag

Your Secrets and Tokens are Secure with Kong Gateway Enterprise 3.5

Product ReleasesNovember 13, 2023

Kong Gateway Enterprise 3.5 is packed with security features to support the use cases demanded by our enterprise customers through major improvements in  Secrets Management  integrations and our  Open-ID Connect (OIDC)  plugin. Additionally, we’ve a

Tom Brightbill

Announcing Kong Operator 2.1

Product ReleasesFebruary 10, 2026

With Kong Ingress Controller, when your Control Plane was hosted in Kong Konnect, and you were using Kubernetes Gateway API, your dataplane, routes, and services were in read-only mode. When using Kong Ingress Controller with Kubernetes Gateway API

Justin Davies

Expanded Observability, Orchestration, and Security with Kong Gateway 3.13

Product ReleasesDecember 18, 2025

As API ecosystems grow more complex, maintaining visibility and security shouldn't be a hurdle. Kong Gateway 3.13 simplifies these challenges with expanded OpenTelemetry support and more flexible orchestration. These new capabilities not only make y

Amit Shah

Kong Cloud Gateways: A Year in Review

Product ReleasesDecember 17, 2025

A quick refresher: Kong Cloud Gateways Kong Cloud Gateways are fully managed, high-performance data planes running on customer-dedicated infrastructure, orchestrated and operated by Kong through Kong Konnect . Customers can choose between: Serverle

Josh Wigginton

Federated Connectivity: Unlocking Data Silos with API Gateways

EngineeringMay 6, 2024

"The whole is more than the sum of its parts." Aristotle is credited with this quote, and it's true in the world of data. Legacy systems typically approached their role in a limited manner.  Each system was intended to be used by a certain user set

Ahmed Koshok

Ready to see Kong in action?

Get a personalized walkthrough of Kong's platform tailored to your architecture, use cases, and scale requirements.

Get a Demo
Powering the API world

Increase developer productivity, security, and performance at scale with the unified platform for API management, AI gateways, service mesh, and ingress controller.

Sign up for Kong newsletter

    • Platform
    • Kong Konnect
    • Kong Gateway
    • Kong AI Gateway
    • Kong Insomnia
    • Developer Portal
    • Gateway Manager
    • Cloud Gateway
    • Get a Demo
    • Explore More
    • Open Banking API Solutions
    • API Governance Solutions
    • Istio API Gateway Integration
    • Kubernetes API Management
    • API Gateway: Build vs Buy
    • Kong vs Postman
    • Kong vs MuleSoft
    • Kong vs Apigee
    • Documentation
    • Kong Konnect Docs
    • Kong Gateway Docs
    • Kong Mesh Docs
    • Kong AI Gateway
    • Kong Insomnia Docs
    • Kong Plugin Hub
    • Open Source
    • Kong Gateway
    • Kuma
    • Insomnia
    • Kong Community
    • Company
    • About Kong
    • Customers
    • Careers
    • Press
    • Events
    • Contact
    • Pricing
  • Terms
  • Privacy
  • Trust and Compliance
  • © Kong Inc. 2026