Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service. The attacker requests a large amount of data from a specified resource over multiple streams. They manipulate window size and stream priority to force the server to queue the data in 1-byte chunks. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Apache
Subscribe
|
Traffic Server
Subscribe
|
|
Apple
Subscribe
|
|
|
Canonical
Subscribe
|
Ubuntu Linux
Subscribe
|
|
Debian
Subscribe
|
Debian Linux
Subscribe
|
|
F5
Subscribe
|
Nginx
Subscribe
|
|
Fedoraproject
Subscribe
|
Fedora
Subscribe
|
|
Mcafee
Subscribe
|
Web Gateway
Subscribe
|
|
Nodejs
Subscribe
|
Node.js
Subscribe
|
|
Opensuse
Subscribe
|
Leap
Subscribe
|
|
Oracle
Subscribe
|
|
|
Redhat
Subscribe
|
Amq Broker
Subscribe
Enterprise Linux
Subscribe
Jboss Core Services
Subscribe
Jboss Enterprise Application Platform
Subscribe
Jboss Enterprise Application Platform Cd
Subscribe
Jboss Enterprise Application Platform Eus
Subscribe
Jboss Fuse
Subscribe
Openshift Application Runtimes
Subscribe
Openshift Service Mesh
Subscribe
Quay
Subscribe
Rhel Software Collections
Subscribe
Service Mesh
Subscribe
Software Collections
Subscribe
|
|
Synology
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-4505-1 | nginx security update |
Debian DSA |
DSA-4511-1 | nghttp2 security update |
Debian DSA |
DSA-4669-1 | nodejs security update |
Ubuntu USN |
USN-4099-1 | nginx vulnerabilities |
Ubuntu USN |
USN-6754-1 | nghttp2 vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 14 Jan 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:o:synology:diskstation_manager:6.2:*:*:*:*:*:*:* |
Mon, 26 Aug 2024 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat jboss Enterprise Application Platform Eus
|
|
| CPEs | cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.1::el7 | |
| Vendors & Products |
Redhat jboss Enterprise Application Platform Eus
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: certcc
Published:
Updated: 2024-08-04T21:54:44.157Z
Reserved: 2019-03-01T00:00:00
Link: CVE-2019-9511
No data.
Status : Modified
Published: 2019-08-13T21:15:12.223
Modified: 2025-01-14T19:29:55.853
Link: CVE-2019-9511
OpenCVE Enrichment
No data.
Debian DSA
Ubuntu USN