CVE-2019-9518

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Aug 13, 2019
Updated: Jan 14, 2025
CWE ID 400
CWE ID 770

Summary

CVE-2019-9518 is a denial-of-service vulnerability affecting some HTTP/2 implementations. An attacker can exploit this issue by sending a continuous stream of empty frames without the end-of-stream flag. These frames, which can be of various types such as DATA, HEADERS, CONTINUATION, or PUSH_PROMISE, cause the peer to spend an excessive amount of CPU processing them, even though they have no payload. As a result, the targeted system can become unresponsive, leading to a denial-of-service condition.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Nodejs Node.js
  • McAfee Web Gateway
  • Apache Traffic Server
  • Apache Software Foundation Traffic Server
  • Debian

Affected Vendors

  • Debian
  • Red Hat
  • Fedora Project
  • McAfee
  • Apache Software Foundation