CVE-2019-9517

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Aug 13, 2019
Updated: Jan 14, 2025
CWE ID 400
CWE ID 770

Summary

CVE-2019-9517 is a cybersecurity vulnerability affecting certain HTTP/2 implementations. The issue stems from unconstrained internal data buffering, which can result in denial-of-service (DoS) attacks. An attacker takes advantage of this flaw by opening an HTTP/2 window for data transfer, but keeps the TCP window closed. Subsequently, they send a barrage of requests for large response objects, causing the server to consume excessive memory and CPU resources as it attempts to process and buffer the data.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Nodejs Node.js
  • McAfee Web Gateway
  • Apache Traffic Server
  • Apache Software Foundation Apache HTTP Server
  • Debian

Affected Vendors

  • Apache Corporation
  • Debian
  • Red Hat
  • Fedora Project
  • Apache Software Foundation