Vulnerability Intelligence Report
Some HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of service
CVE-2019-9516
Some HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of service. The attacker sends a stream of headers with a 0-length header name and 0-length header value, optionally Huffman encoded into 1-byte or greater headers. Some implementations allocate memory for these headers and keep the allocation alive until the session dies. This can consume excess memory.
No Active Exploit Signals
CVSS Base Score
7.5
HIGH
Exploitability:3.9
Impact Score:3.6
EPSS Probability:57.46%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-400 ↗CWE-400 Uncontrolled Resource Consumption
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| apple | swiftnio | all |
| apple | mac_os_x | all |
| canonical | ubuntu_linux | 16.04, 18.04, 19.04 |
| apache | traffic_server | all |
| debian | debian_linux | 9.0, 10.0 |
| fedoraproject | fedora | 30, 29, 32 |
| synology | skynas | all |
| synology | diskstation_manager | 6.2 |
| synology | vs960hd_firmware | all |
| synology | vs960hd | all |
| opensuse | leap | 15.0, 15.1 |
| redhat | jboss_core_services | 1.0 |
| redhat | jboss_enterprise_application_platform | 7.2.0, 7.3.0 |
| redhat | openshift_service_mesh | 1.0 |
| redhat | quay | 3.0.0 |
| redhat | software_collections | 1.0 |
| redhat | enterprise_linux | 8.0 |
| oracle | graalvm | 19.2.0 |
| mcafee | web_gateway | all |
| f5 | nginx | all |
| nodejs | node.js | all |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
57.461%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | CERT/CC · CERT · USA |
| Reserved | 2019-03-01T00:00:00 |
| Published | 2019-08-13T20:50:59 |
| Last Updated | 2024-08-04T21:54:44 |
Community Chatter & Buzz