PT-2019-2979 · Http/2+8 · Http/2+8

Piotr Sikora

·

Published

2019-08-13

·

Updated

2026-05-18

·

CVE-2019-9518

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions HTTP/2 implementations (affected versions not specified)
Description The issue is related to a flood of empty frames in HTTP/2 implementations, which can lead to a denial of service. An attacker sends a stream of frames with an empty payload and without the end-of-stream flag. These frames can be DATA, HEADERS, CONTINUATION, and/or PUSH PROMISE. The peer spends time processing each frame disproportionate to attack bandwidth, consuming excess CPU.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Resource Exhaustion

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2019:2925
ALT-PU-2019-3050
ALT-PU-2020-2195
BDU:2019-02957
CESA-2019_2925
CLEANSTART-2026-BD71263
CLEANSTART-2026-IS74202
CLEANSTART-2026-JR35772
CLEANSTART-2026-JY06700
CLEANSTART-2026-KN34553
CLEANSTART-2026-KZ45320
CLEANSTART-2026-LJ44720
CLEANSTART-2026-LN12820
CLEANSTART-2026-TX00223
CLEANSTART-2026-WI75198
CVE-2019-9518
DSA-4520-1
MGASA-2020-0372
OPENSUSE-SU-2019:2114-1
OPENSUSE-SU-2019:2115-1
OPENSUSE-SU-2019_2114-1
OPENSUSE-SU-2019_2115-1
RHSA-2019:2925
RHSA-2019:2939
RHSA-2019:2955
RHSA-2019_2925
RLSA-2019:2925
SUSE-SU-2019:14246-1
SUSE-SU-2019:2254-1
SUSE-SU-2019:2259-1
SUSE-SU-2019:2260-1
SUSE-SU-2019_14246-1
SUSE-SU-2020:0059-1
USN-4866-1

Affected Products

Alt Linux
Almalinux
Centos
Http/2
Red Hat
Rocky Linux
Suse
Ubuntu
Windows