PT-2019-3015 · Node.Js Foundation+11 · Node.Js+11

Jonathan Looney

·

Published

2019-03-20

·

Updated

2026-05-18

·

CVE-2019-9511

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions HTTP/2 implementations (affected versions not specified) nginx (affected versions not specified) Node.js (affected versions not specified) Apache HTTP Server (affected versions not specified) Windows (affected versions not specified)
Description The issue is related to window size manipulation and stream prioritization manipulation in HTTP/2 implementations, potentially leading to a denial of service. An attacker can request a large amount of data from a specified resource over multiple streams, manipulating window size and stream priority to force the server to queue the data in 1-byte chunks. This can consume excess CPU, memory, or both, depending on how efficiently the data is queued.
Recommendations For HTTP/2 implementations, consider disabling the HTTP/2 protocol until a patch is available. For nginx, restrict access to the HTTP/2 module to minimize the risk of exploitation. For Node.js, avoid using the HTTP/2 module in production environments until the issue is resolved. For Apache HTTP Server, consider disabling the HTTP/2 protocol or restricting access to the affected module to minimize the risk of exploitation. For Windows, apply configuration changes to restrict the use of HTTP/2 or disable it temporarily until a fix is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Resource Exhaustion

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2019:2799
ALSA-2019:2925
ALT-PU-2019-2600
ALT-PU-2019-2601
ALT-PU-2019-2823
ALT-PU-2019-3050
ALT-PU-2020-2194
ALT-PU-2020-2195
BDU:2019-02994
BDU:2019-03782
CESA-2019_2692
CESA-2019_2799
CESA-2019_2925
CLEANSTART-2026-AF45008
CLEANSTART-2026-BA37192
CLEANSTART-2026-BD71263
CLEANSTART-2026-IS74202
CLEANSTART-2026-JR35772
CLEANSTART-2026-JY06700
CLEANSTART-2026-KN34553
CLEANSTART-2026-KZ45320
CLEANSTART-2026-LJ44720
CLEANSTART-2026-LN12820
CLEANSTART-2026-MQ02912
CLEANSTART-2026-TX00223
CLEANSTART-2026-WI75198
CLEANSTART-2026-XB16901
CLEANSTART-2026-ZN32454
CLEANSTART-2026-ZT77083
CVE-2019-9511
DSA-4505-1
DSA-4511-1
DSA-4669-1
MGASA-2019-0291
MGASA-2019-0342
MGASA-2020-0372
OPENSUSE-SU-2019:2114-1
OPENSUSE-SU-2019:2115-1
OPENSUSE-SU-2019:2120-1
OPENSUSE-SU-2019:2232-1
OPENSUSE-SU-2019:2234-1
OPENSUSE-SU-2019:2264-1
OPENSUSE-SU-2019_2114-1
OPENSUSE-SU-2019_2115-1
OPENSUSE-SU-2019_2120-1
OPENSUSE-SU-2019_2232-1
OPENSUSE-SU-2019_2234-1
OPENSUSE-SU-2019_2264-1
OPENSUSE-SU-2024:11091-1
OPENSUSE-SU-2024:11092-1
RHSA-2019:2692
RHSA-2019:2745
RHSA-2019:2746
RHSA-2019:2775
RHSA-2019:2799
RHSA-2019:2925
RHSA-2019:2939
RHSA-2019:2946
RHSA-2019:2949
RHSA-2019:2955
RHSA-2019:3041
RHSA-2019:3932
RHSA-2019:3933
RHSA-2019:4018
RHSA-2019:4019
RHSA-2019:4020
RHSA-2019_2692
RHSA-2019_2799
RHSA-2019_2925
RHSA-2024:5856
RLSA-2019:2799
RLSA-2019:2925
SUSE-SU-2019:14246-1
SUSE-SU-2019:2254-1
SUSE-SU-2019:2259-1
SUSE-SU-2019:2260-1
SUSE-SU-2019:2309-1
SUSE-SU-2019:2473-1
SUSE-SU-2019:2559-1
SUSE-SU-2019_14246-1
SUSE-SU-2019_2254-1
SUSE-SU-2019_2259-1
SUSE-SU-2019_2260-1
SUSE-SU-2019_2473-1
SUSE-SU-2019_2559-1
SUSE-SU-2020:0059-1
SUSE-SU-2021:0932-1
USN-4099-1
USN-6754-1

Affected Products

Alt Linux
Almalinux
Apache Http Server
Centos
Linuxmint
Nginx
Node.Js
Red Hat
Rocky Linux
Suse
Ubuntu
Windows