CVE-2019-9518
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Aug 13, 2019
Updated: Jan 14, 2025
CWE ID 400
CWE ID 770
Summary
CVE-2019-9518 is a denial-of-service vulnerability affecting some HTTP/2 implementations. An attacker can exploit this issue by sending a continuous stream of empty frames without the end-of-stream flag. These frames, which can be of various types such as DATA, HEADERS, CONTINUATION, or PUSH_PROMISE, cause the peer to spend an excessive amount of CPU processing them, even though they have no payload. As a result, the targeted system can become unresponsive, leading to a denial-of-service condition.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Nodejs Node.js
- McAfee Web Gateway
- Apache Traffic Server
- Apache Software Foundation Traffic Server
- Debian
Affected Vendors
- Debian
- Red Hat
- Fedora Project
- McAfee
- Apache Software Foundation