Skip to content

Comment on HTTP/2 rapid reset attack impacting Nginx products

Comments

Anyone know if it affects Caddy?

Patched in 2.7.5: https://github.com/caddyserver/caddy/releases/tag/v2.7.5

I think it might also require a patched version of Go.

You could 'caddy upgrade' pretty quickly to get the patch (servers had updated go), though the release number bump didn't happen immediately.

Running the same now, or pulling a new binary, using xcaddy, etc. will get you 2.7.5 which also includes some other small fixes not related to rapid reset.

There are new versions of Go which have this CVE patched already published and available for download.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.