CVE-2019-9516
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Aug 13, 2019
Updated: Jan 14, 2025
CWE ID 400
CWE ID 770
Summary
CVE-2019-9516 refers to a header leak vulnerability in some HTTP/2 implementations. An attacker can exploit this issue by sending a stream of headers with zero-length names and values, potentially leading to a denial of service. The attacker can optionally Huffman encode these headers into one-byte or greater lengths. Affected implementations allocate memory for these malicious headers, keeping the allocations alive until the session ends. This can result in excessive memory consumption.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Nodejs Node.js
- F5-NGINX
- McAfee Web Gateway
- Apache Traffic Server
- Debian
Affected Vendors
- Debian
- Red Hat
- Fedora Project
- McAfee
- Apache Software Foundation