The vulnerability in HTTP/2 protocol, known as HTTP/2 Rapid Reset, has potential for exploitation leading to devastating DDoS attacks.
It’s a fact: over 60% of the web uses HTTP/2, making the vulnerability a high-risk issue. Attacks have leveraged this flaw, leading to some of the most large-scale DDoS attacks ever witnessed.
Sucuri customers already enjoy robust protection against HTTP/2 rapid onset attacks. But if you’re not currently on our platform, we’re ready to help. Our web application firewall offers extensive protection against HTTP/2, denial of service attacks, and other threats.
Sanitizes traffic via heuristic and signature-based techniques before it reaches your server.
Detects and mitigates HTTP/2 rapid reset, CVE-2023-44487, and DDoS attacks of every size.
Support for load balancing and server failover configurations to help keep you online.
Stops unknown vulnerability exploitation attempts against your website and server environment.
Uses a globally distributed Anycast Network and secure content delivery to handle large traffic spikes.
Correlates attack data to anticipate malicious behavior and protect your from malicious threats.
Built for all platforms and custom sites
Get Protected from HTTP/2 Rapid Reset & DDoS
Protection is just a click away. Our web application firewall automatically blocks fake traffic and DDoS attacks of all sizes, without interfering with your legitimate traffic. Professional support available 24/7.
Website Application Firewall (WAF
![]()
Intrusion Detection System
![]()
Stop Hacks (Virtual Patching/Hardening)
![]()
Firewall Protection – HTTPS & PCI Compliant
![]()
Advanced DDoS Mitigation
![]()
CDN Speed Enhancements
![]()
High Availability/Load Balancing
![]()
Brute Force Protection
![]()
Protected Pages
![]()
Heuristic Correlation Engine
![]()
Fast Page Speed
![]()
Reduced Server Load
![]()
Smart Caching Options
![]()
CMS & Hosting Compatibility
Agnostic
Support Requests
Direct to Tier 3 Ticket Support
Bandwidth Limit
Unlimited
30 Day Money Back Guarantee
![]()
Sucuri Dashboard API
![]()
Before Sucuri, we had limited visibility into security threats and we spent a lot of time investigating and manually cleaning up breaches. Now we can get ahead of security issues and focus our attention elsewhere-which is a huge help when you have 50+ websites to support.
ITW Consulting
When it comes to website security, we want to provide our customers with the most exemplary service available. That’s why we have partnered with Sucuri. To expand on our commitment to offer only the safest hosting environment, Sucuri offers the best website malware cleanup, protection, and monitoring services in the business.
Vanessa Vasile, InMotion Hosting
Sucuri is more of an insurance policy to prevent problems. It does all of the work for us by blocking all things malicious. We are a web hosting provider, so how would it look if our own site was compromised or down?
Anton Resnick, Webhosting.net
Custom security incident and event management integration.
Custom pages for traffic blocked by the web application firewall.
Convenient payment options at monthly intervals.
Customized onboarding, education, and a dedicated account specialist.
Beat the queue and promptly address website security issues.
Role-based account access to the Sucuri dashboard interface.
Account executives available 24/7/365 for full-event escalation.
Set up and customize alerts and notifications for Slack.
Priority response escalation services for faster resolutions.
* Additional costs for Agency and Enterprise features.
What is the HTTP/2 Rapid Reset vulnerability (CVE-2023-44487)?
The HTTP/2 Rapid Reset vulnerability (CVE-2023-44487) allows attackers to flood servers with rapid stream resets, overwhelming resources and causing denial-of-service (DoS) conditions. It’s a protocol-level flaw that has been exploited in large-scale DDoS attacks.
How does Sucuri protect against HTTP/2 Rapid Reset attacks?
Sucuri’s Web Application Firewall (WAF) uses signature detection, heuristic analysis, and machine learning to identify and block HTTP/2 Rapid Reset exploits in real time. Our global infrastructure ensures uptime and performance even during attack surges.
Is CVE-2023-44487 a zero-day vulnerability
Yes, CVE-2023-44487 was initially exploited as a zero-day, meaning it was actively used in attacks before public disclosure. Sucuri’s proactive threat detection helped mitigate the risk before widespread awareness.
Can Sucuri’s WAF prevent future zero-day vulnerabilities?
Absolutely. Sucuri’s WAF is designed to detect anomalies and unknown threats using behavioral analysis and machine learning, offering protection even against emerging zero-day exploits.
Is this protection available for all websites?
Yes. Sucuri’s WAF supports websites across all platforms, including WordPress, Joomla, Magento, and custom-built sites. Our protection is platform-agnostic and works at the protocol level.
How does Sucuri compare to other security providers?
Unlike general DDoS protection tools, Sucuri specifically addresses HTTP/2 vulnerabilities like CVE-2023-44487. We offer personalized onboarding, advanced threat detection, and enterprise customization that many competitors lack.