CVE-2019-9512
Last modified
CVE-2019-9512 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Some HTTP/2 implementations are vulnerable to ping floods, potentially leading to a denial of service. The attacker sends continual pings to an HTTP/2 peer, causing the peer to build an internal queue of responses. EPSS estimates a 83.43% chance of exploitation in the next 30 days.
Description
Some HTTP/2 implementations are vulnerable to ping floods, potentially leading to a denial of service. The attacker sends continual pings to an HTTP/2 peer, causing the peer to build an internal queue of responses. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apple | Swiftnio | >= 1.0.0, <= 1.4.0 |
| Apache | Traffic Server | >= 6.0.0, <= 6.2.3 |
| Apache | Traffic Server | >= 7.0.0, <= 7.1.6 |
| Apache | Traffic Server | >= 8.0.0, <= 8.0.3 |
| Debian | Debian Linux | 10.0 |
| Nodejs | Node.Js | >= 8.0.0, <= 8.8.1 |
| Nodejs | Node.Js | >= 8.9.0, < 8.16.1 |
| Nodejs | Node.Js | >= 10.0.0, <= 10.12.0 |
| Nodejs | Node.Js | >= 10.13.0, < 10.16.3 |
| Nodejs | Node.Js | >= 12.0.0, < 12.8.1 |
References
- https://lists.opensuse.org/opensuse-security-announce/2019-08/msg00076.htmlMailing List, Third Party Advisory
- https://lists.opensuse.org/opensuse-security-announce/2019-09/msg00002.htmlMailing List, Third Party Advisory
- https://lists.opensuse.org/opensuse-security-announce/2019-09/msg00011.htmlMailing List, Third Party Advisory
- https://lists.opensuse.org/opensuse-security-announce/2019-09/msg00021.htmlMailing List, Third Party Advisory
- https://lists.opensuse.org/opensuse-security-announce/2019-09/msg00031.htmlMailing List, Third Party Advisory
- https://lists.opensuse.org/opensuse-security-announce/2019-09/msg00032.htmlMailing List, Third Party Advisory
- https://lists.opensuse.org/opensuse-security-announce/2019-09/msg00038.htmlMailing List, Third Party Advisory
- https://seclists.org/fulldisclosure/2019/Aug/16Mailing List, Third Party Advisory
- https://www.openwall.com/lists/oss-security/2019/08/20/1Mailing List, Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2594Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2661Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2682Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2690Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2726Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2766Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2769Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2796Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2861Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2925Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2939Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2955Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2966Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3131Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3245Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3265Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3892Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3906Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4018Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4019Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4020Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4021Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4040Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4041Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4042Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4045Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4269Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4273Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4352Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0406Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0727Third Party Advisory
- https://kb.cert.org/vuls/id/605641/Third Party Advisory, US Government Resource
- https://kc.mcafee.com/corporate/index?page=content&id=SB10296Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/12/msg00011.htmlMailing List, Third Party Advisory
- https://seclists.org/bugtraq/2019/Aug/24Mailing List, Third Party Advisory
- https://seclists.org/bugtraq/2019/Aug/31Mailing List, Third Party Advisory
- https://seclists.org/bugtraq/2019/Aug/43Mailing List, Third Party Advisory
- https://seclists.org/bugtraq/2019/Sep/18Mailing List, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20190823-0001/Third Party Advisory
- https://security.netapp.com/advisory/ntap-20190823-0004/Third Party Advisory
- https://security.netapp.com/advisory/ntap-20190823-0005/Third Party Advisory
- https://support.f5.com/csp/article/K98053339Third Party Advisory
- https://usn.ubuntu.com/4308-1/Third Party Advisory
- https://www.debian.org/security/2019/dsa-4503Third Party Advisory
- https://www.debian.org/security/2019/dsa-4508Third Party Advisory
- https://www.debian.org/security/2019/dsa-4520Third Party Advisory
- https://www.synology.com/security/advisory/Synology_SA_19_33Third Party Advisory
- https://lists.opensuse.org/opensuse-security-announce/2019-08/msg00076.htmlMailing List, Third Party Advisory
- https://lists.opensuse.org/opensuse-security-announce/2019-09/msg00002.htmlMailing List, Third Party Advisory
- https://lists.opensuse.org/opensuse-security-announce/2019-09/msg00011.htmlMailing List, Third Party Advisory
- https://lists.opensuse.org/opensuse-security-announce/2019-09/msg00021.htmlMailing List, Third Party Advisory
- https://lists.opensuse.org/opensuse-security-announce/2019-09/msg00031.htmlMailing List, Third Party Advisory
- https://lists.opensuse.org/opensuse-security-announce/2019-09/msg00032.htmlMailing List, Third Party Advisory
- https://lists.opensuse.org/opensuse-security-announce/2019-09/msg00038.htmlMailing List, Third Party Advisory
- https://seclists.org/fulldisclosure/2019/Aug/16Mailing List, Third Party Advisory
- https://www.openwall.com/lists/oss-security/2019/08/20/1Mailing List, Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2594Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2661Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2682Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2690Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2726Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2766Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2769Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2796Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2861Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2925Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2939Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2955Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2966Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3131Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3245Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3265Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3892Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3906Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4018Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4019Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4020Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4021Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4040Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4041Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4042Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4045Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4269Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4273Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4352Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0406Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0727Third Party Advisory
- https://kb.cert.org/vuls/id/605641/Third Party Advisory, US Government Resource
- https://kc.mcafee.com/corporate/index?page=content&id=SB10296Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/12/msg00011.htmlMailing List, Third Party Advisory
- https://seclists.org/bugtraq/2019/Aug/24Mailing List, Third Party Advisory
- https://seclists.org/bugtraq/2019/Aug/31Mailing List, Third Party Advisory
- https://seclists.org/bugtraq/2019/Aug/43Mailing List, Third Party Advisory
- https://seclists.org/bugtraq/2019/Sep/18Mailing List, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20190823-0001/Third Party Advisory
- https://security.netapp.com/advisory/ntap-20190823-0004/Third Party Advisory
- https://security.netapp.com/advisory/ntap-20190823-0005/Third Party Advisory
- https://support.f5.com/csp/article/K98053339Third Party Advisory
- https://usn.ubuntu.com/4308-1/Third Party Advisory
- https://www.debian.org/security/2019/dsa-4503Third Party Advisory
- https://www.debian.org/security/2019/dsa-4508Third Party Advisory
- https://www.debian.org/security/2019/dsa-4520Third Party Advisory
- https://www.synology.com/security/advisory/Synology_SA_19_33Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-9512?
How severe is CVE-2019-9512?
How do I fix CVE-2019-9512?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-9506The Bluetooth BR/EDR specification up to and including versi…8.1
- CVE-2019-9507The web interface of the Vertiv Avocent UMG-4000 version 4.2…7.2
- CVE-2019-9508The web interface of the Vertiv Avocent UMG-4000 version 4.2…3.5
- CVE-2019-9509The web interface of the Vertiv Avocent UMG-4000 version 4.2…5.4
- CVE-2019-9510A vulnerability in Microsoft Windows 10 1803 and Windows Ser…7.8
- CVE-2019-9511Some HTTP/2 implementations are vulnerable to window size ma…7.5
- CVE-2019-9513Some HTTP/2 implementations are vulnerable to resource loops…7.5
- CVE-2019-9514Some HTTP/2 implementations are vulnerable to a reset flood,…7.5
- CVE-2019-9515Some HTTP/2 implementations are vulnerable to a settings flo…7.5
- CVE-2019-9516Some HTTP/2 implementations are vulnerable to a header leak,…6.5
- CVE-2019-9517Some HTTP/2 implementations are vulnerable to unconstrained …7.5
- CVE-2019-9518Some HTTP/2 implementations are vulnerable to a flood of emp…7.5
Are you affected by CVE-2019-9512?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
