惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
博客园 - 聂微东
博客园 - 叶小钗
爱范儿
爱范儿
罗磊的独立博客
Hugging Face - Blog
Hugging Face - Blog
阮一峰的网络日志
阮一峰的网络日志
S
SegmentFault 最新的问题
Apple Machine Learning Research
Apple Machine Learning Research
美团技术团队
T
Tailwind CSS Blog
博客园 - 司徒正美
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
宝玉的分享
宝玉的分享
量子位
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
The Cloudflare Blog
人人都是产品经理
人人都是产品经理
小众软件
小众软件
博客园 - 【当耐特】
博客园 - 三生石上(FineUI控件)
V
Visual Studio Blog
雷峰网
雷峰网
酷 壳 – CoolShell
酷 壳 – CoolShell

Netlify Changelog

Gemini 3.5 Flash now available in Agent Runners 4 Nuxt CVEs: what Netlify users need to know Gemini 3.5 Flash now available in AI Gateway Agent Runners workflow improvements Next.js & React security release (May 2026): what to know Block project transfers out of your team Gemini 3.1 Flash-Lite now available in AI Gateway OpenAI GPT-5.5 Instant now available in AI Gateway New `netlify logs` CLI command Deploy to Netlify with Stripe Projects Netlify Database is now generally available OpenAI GPT-5.5 and GPT-5.5 Pro in AI Gateway & Agent Runners Rename an agent run GPT Image 2 now available in AI Gateway New frontend-design skill for Agent Runners Claude Opus 4.7 now available in AI Gateway and Agent Runners Pricing updates for Credit-based plans New sorting and filter controls on the Members page Netlify Database GA coming soon, no new databases for now Deploy logs streaming is now faster Netlify CLI adds prompt-based creation and anonymous deploys Deploy from Codex with the Netlify Plugin Hydrogen with React Router 7 now supported on Netlify Monitor credit usage by day Invoices for Enterprise Available on the Billing Page AI app development on production infrastructure with Netlify Introducing Prompt Templates OpenAI GPT-5.4 Nano and GPT-5.4 Mini in AI Gateway Change your pricing plan Internal Builder Role & Project Access Controls
Netlify Successfully Mitigates CVE-2023-44487
Nahrin Jalal · 2023-10-13 · via Netlify Changelog

Your trust and security are of utmost importance to us, and we continue to work diligently to ensure that your data remains safe and secure. Today, we are pleased to announce that we have successfully mitigated the vulnerabilities identified in CVE-2023-44487.

What do Netlify customers need to do?

At this time there is no action required on the part of Netlify customers.

A substantial portion of our services received protection from our cloud service providers, which took proactive measures by deploying updates to address the vulnerability before it became publicly known. For services requiring manual attention, we achieved successful patching of all critical systems within a 12-hour time frame from the moment patches became available.

Understanding CVE-2023-44487

CVE-2023-44487, as cataloged by the Common Vulnerabilities and Exposures (CVE) system, is a denial of service (DoS) vulnerability that impacts any internet exposed HTTP/2 endpoints and is known as the HTTP/2 Rapid Reset Attack. In a Rapid Reset Attack, an attacker sends a large number of HTTP/2 reset frames in a very short period of time to a target server. These reset frames are a legitimate part of the HTTP/2 protocol and are used to signal the abrupt termination of a stream. However, when sent in rapid succession in a coordinated attack, they can overwhelm the server’s resources and disrupt its normal operation.

The goal of a Rapid Reset Attack is to exhaust the server’s resources, such as CPU or memory, by forcing it to process a large number of reset frames. This can lead to a denial of service (DoS) condition, where legitimate users are unable to access the server or its services due to the excessive resource consumption caused by the attack.

CVE-2023-44487 impacts several packages. Please refer to: https://www.cve.org/CVERecord?id=CVE-2023-44487 for additional information.

Our pledge to security

We understand that your confidence in our services relies on our actions. We pledge to uphold the highest standards of professionalism and security in safeguarding your data and your organization. We wholeheartedly believe that our commitment is reflected in our actions, not just our words.

Stay informed

For updates or inquiries regarding security matters, our dedicated customer support team remains at your service. Feel free to reach out to us if you require further information or assistance by visiting http://www.netlify.com/support.

Thank you for choosing Netlify. We deeply appreciate your trust and remain steadfast in our commitment to maintaining your data and organizational security.