← Back to CVE List
Vulnerability Intelligence Report
Some HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of service

CVE-2019-9516

Some HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of service. The attacker sends a stream of headers with a 0-length header name and 0-length header value, optionally Huffman encoded into 1-byte or greater headers. Some implementations allocate memory for these headers and keep the allocation alive until the session dies. This can consume excess memory.

No Active Exploit Signals
CVSS Base Score
7.5
HIGH
Exploitability:3.9
Impact Score:3.6
EPSS Probability:57.46%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-400 ↗CWE-400 Uncontrolled Resource Consumption

Affected Products & Versions

Vendor Product Affected Versions
apple swiftnio all
apple mac_os_x all
canonical ubuntu_linux 16.04, 18.04, 19.04
apache traffic_server all
debian debian_linux 9.0, 10.0
fedoraproject fedora 30, 29, 32
synology skynas all
synology diskstation_manager 6.2
synology vs960hd_firmware all
synology vs960hd all
opensuse leap 15.0, 15.1
redhat jboss_core_services 1.0
redhat jboss_enterprise_application_platform 7.2.0, 7.3.0
redhat openshift_service_mesh 1.0
redhat quay 3.0.0
redhat software_collections 1.0
redhat enterprise_linux 8.0
oracle graalvm 19.2.0
mcafee web_gateway all
f5 nginx all
nodejs node.js all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
57.461%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityCERT/CC · CERT · USA
Reserved2019-03-01T00:00:00
Published2019-08-13T20:50:59
Last Updated2024-08-04T21:54:44

LINK COPIED TO CLIPBOARD