Blog
  • AI Gateway
  • AI Security
  • AIOps
  • API Security
  • API Gateway
|
    • API Management
    • API Development
    • API Design
    • Automation
    • Service Mesh
    • Insomnia
    • View All Blogs
  1. Home
  2. Blog
  3. Product Releases
  4. Kong Releases Product Updates to Address Novel HTTP/2 'Rapid Reset' DDoS Vulnerability
Product Releases
October 12, 2023
2 min read

Kong Releases Product Updates to Address Novel HTTP/2 'Rapid Reset' DDoS Vulnerability

Tom Brightbill
Group Product Manager

At Kong, the security and reliability of our products have always been paramount. In light of the recent discovery of the Novel HTTP/2 ‘Rapid Reset’ DDoS attack (CVE-2023-44487), we have taken steps to proactively address potential issues. Today we’re providing guidance on how our users can best safeguard their systems. 

What is the HTTP/2 Rapid Reset Attack?

This vulnerability exploits the 'concurrent streaming' capability of HTTP/2. In this attack, a client can flood the server with a very high number of HTTP/2 stream requests that are immediately reset. This causes the server to spend a lot of resources cleaning up these canceled streams. These types of requests are legal in HTTP/2 and a malicious client can defeat existing flood prevention checks with minimal work.

The servers end up spending too much time in cleaning up the canceled streams, thus preventing them from servicing valid traffic, causing a Denial of Service.

We urge customers with HTTP/2-enabled servers to liaise with their web server providers to ensure timely application of essential patches.

Immediate Action Taken by Kong

All supported versions of Kong Gateway, Kong Mesh, and Kuma have been patched and released. The following versions contain a fix for the HTTP/2 rapid reset attack:

  • Kong Gateway Enterprise: 2.8.4.4, 3.1.1.6, 3.2.2.5, 3.3.1.1, 3.4.1.1
  • Kong Gateway OSS: 3.4.2
  • Kong Mesh: 2.0.8, 2.1.7, 2.2.5, 2.3.3, 2.4.3
  • Kuma: 2.0.8, 2.1.7, 2.2.5, 2.3.3, 2.4.3

For users using the Docker official image for Kong OSS, we have submitted an updated version and are waiting for the fix to be merged. To update immediately, please switch to the kong/kong image. For customers using Kong Enterprise images, the updates are available immediately. 

Mitigation Steps

If you cannot immediately update to the latest patches containing our fixes, we recommend the following mitigation steps:

  1. Disable HTTP/2 Support in Kong
  2. Reduce the HTTP/2 keepalive limit

You can find more information about the details of implementing these mitigation measures in the Kong knowledge base.

At Kong, we appreciate the trust you place in us and in our products. We are committed to ensuring the security of our community and will continue to monitor and address vulnerabilities proactively. Lastly, we highly recommend that all of our users evaluate their systems, apply the necessary patches, and follow the mitigation steps provided.

API SecurityAPI Gateway

More on this topic

Webinars

Quarterly Platform Updates & Roadmap Webinar

Demos

How Should API Gateways And Service Mesh Fit Into Your API Platform?

See Kong in action

Accelerate deployments, reduce vulnerabilities, and gain real-time visibility. 

Get a Demo
Topics
API SecurityAPI Gateway
Share on Social
Tom Brightbill
Group Product Manager

Recommended posts

Kong Event Gateway: Unifying APIs and Events in a Single API Platform

Kong Logo
Product ReleasesMay 13, 2025

Kong customers include some of the most forward-thinking, tech-savvy organizations in the world. And while we’re proud to help them innovate through traditional APIs, the reality is that their ambitions don’t stop there. Increasingly, our customers a

Umair Waheed

Kong Gateway 3.9: Extended AI Support and Enhanced Security

Kong Logo
Product ReleasesDecember 20, 2024

Today we're excited to announce Kong Gateway 3.9!  Since unveiling Kong Gateway 3.8 at API Summit 2024 just a few months ago, we’ve been busy making important updates and improvements to Kong Gateway. This release introduces new functionality arou

Alex Drag

Your Secrets and Tokens are Secure with Kong Gateway Enterprise 3.5

Kong Logo
Product ReleasesNovember 13, 2023

Kong Gateway Enterprise 3.5 is packed with security features to support the use cases demanded by our enterprise customers through major improvements in  Secrets Management  integrations and our  Open-ID Connect (OIDC)  plugin. Additionally, we’ve a

Tom Brightbill

Expanded Observability, Orchestration, and Security with Kong Gateway 3.13

Kong Logo
Product ReleasesDecember 18, 2025

As API ecosystems grow more complex, maintaining visibility and security shouldn't be a hurdle. Kong Gateway 3.13 simplifies these challenges with expanded OpenTelemetry support and more flexible orchestration. These new capabilities not only make y

Amit Shah

Kong Cloud Gateways: A Year in Review

Kong Logo
Product ReleasesDecember 17, 2025

A quick refresher: Kong Cloud Gateways Kong Cloud Gateways are fully managed, high-performance data planes running on customer-dedicated infrastructure, orchestrated and operated by Kong through Kong Konnect . Customers can choose between: Serverle

Josh Wigginton

Introducing kongctl

Kong Logo
Product ReleasesOctober 15, 2025

Built for developers We’ve taken the best parts of Terraform, deck, the AWS CLI, and more of your favorite tools and combined them into something that’s really special. kongctl takes inspiration from the AWS CLI, with support for profiles. Profiles

Rick Spurgeon

Announcing Kong Operator 2.0

Kong Logo
Product ReleasesOctober 1, 2025

Simplified controller configuration When using the Kong Ingress Controller, a significant amount of effort was needed to apply configuration to the controller by setting environment variables. The new ControlPlane resource greatly simplifies this an

Justin Davies

Ready to see Kong in action?

Get a personalized walkthrough of Kong's platform tailored to your architecture, use cases, and scale requirements.

Get a Demo
Powering the API world

Increase developer productivity, security, and performance at scale with the unified platform for API management, AI gateways, service mesh, and ingress controller.

Sign up for Kong newsletter

    • Platform
    • Kong Konnect
    • Kong Gateway
    • Kong AI Gateway
    • Kong Insomnia
    • Developer Portal
    • Gateway Manager
    • Cloud Gateway
    • Get a Demo
    • Explore More
    • Open Banking API Solutions
    • API Governance Solutions
    • Istio API Gateway Integration
    • Kubernetes API Management
    • API Gateway: Build vs Buy
    • Kong vs Postman
    • Kong vs MuleSoft
    • Kong vs Apigee
    • Documentation
    • Kong Konnect Docs
    • Kong Gateway Docs
    • Kong Mesh Docs
    • Kong AI Gateway
    • Kong Insomnia Docs
    • Kong Plugin Hub
    • Open Source
    • Kong Gateway
    • Kuma
    • Insomnia
    • Kong Community
    • Company
    • About Kong
    • Customers
    • Careers
    • Press
    • Events
    • Contact
    • Pricing
  • Terms
  • Privacy
  • Trust and Compliance
  • © Kong Inc. 2026