← Back to CVE List
Vulnerability Intelligence Report
Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service

CVE-2019-9511

Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service. The attacker requests a large amount of data from a specified resource over multiple streams. They manipulate window size and stream priority to force the server to queue the data in 1-byte chunks. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both.

No Active Exploit Signals
CVSS Base Score
7.5
HIGH
Exploitability:3.9
Impact Score:3.6
EPSS Probability:59.55%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-400 ↗CWE-400 Uncontrolled Resource Consumption

Affected Products & Versions

Vendor Product Affected Versions
apple swiftnio all
apple mac_os_x all
canonical ubuntu_linux 16.04, 18.04, 19.04
apache traffic_server all
debian debian_linux 9.0, 10.0
synology skynas all
synology diskstation_manager 6.2
synology vs960hd_firmware all
synology vs960hd all
fedoraproject fedora 29, 30
opensuse leap 15.0, 15.1
redhat jboss_core_services 1.0
redhat jboss_enterprise_application_platform 7.2.0, 7.3.0
redhat openshift_service_mesh 1.0
redhat quay 3.0.0
redhat software_collections 1.0
redhat enterprise_linux 8.0
oracle graalvm 19.2.0
mcafee web_gateway all
f5 nginx all
oracle enterprise_communications_broker 3.1.0, 3.2.0
nodejs node.js all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
59.547%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityCERT/CC · CERT · USA
Reserved2019-03-01T00:00:00
Published2019-08-13T20:50:59
Last Updated2024-08-04T21:54:44

LINK COPIED TO CLIPBOARD