CVE-2019-9511

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Aug 13, 2019
Updated: Jan 14, 2025
CWE ID 400
CWE ID 770

Summary

CVE-2019-9511 is a vulnerability affecting some HTTP/2 implementations. Attackers can exploit this weakness by manipulating window size and stream prioritization, leading to a denial-of-service condition. The assailant sends multiple requests for large data sets over different streams. By controlling window size and stream priority, they force the server to process these requests in tiny 1-byte chunks. The excessive CPU and memory usage required to queue and process these chunks can significantly impact server performance.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Nodejs Node.js
  • F5-NGINX
  • McAfee Web Gateway
  • Apache Traffic Server
  • Debian

Affected Vendors

  • Debian
  • Red Hat
  • Fedora Project
  • McAfee
  • Apache Software Foundation