CVE-2019-9516

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Aug 13, 2019
Updated: Jan 14, 2025
CWE ID 400
CWE ID 770

Summary

CVE-2019-9516 refers to a header leak vulnerability in some HTTP/2 implementations. An attacker can exploit this issue by sending a stream of headers with zero-length names and values, potentially leading to a denial of service. The attacker can optionally Huffman encode these headers into one-byte or greater lengths. Affected implementations allocate memory for these malicious headers, keeping the allocations alive until the session ends. This can result in excessive memory consumption.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Nodejs Node.js
  • F5-NGINX
  • McAfee Web Gateway
  • Apache Traffic Server
  • Debian

Affected Vendors

  • Debian
  • Red Hat
  • Fedora Project
  • McAfee
  • Apache Software Foundation