PT-2019-3473 · Apache+8 · Apache Http Server+9

Jonathan Looney

·

Published

2019-03-20

·

Updated

2026-05-18

·

CVE-2019-9517

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Apache Traffic Server versions (affected versions not specified) Apache HTTP Server versions (affected versions not specified) Node.js versions (affected versions not specified)
Description The issue is related to errors in the mechanism controlling resource expenditure in HTTP/2 implementations, potentially leading to a denial of service. An attacker can exploit this by opening the HTTP/2 window, allowing the peer to send without constraint, while keeping the TCP window closed, preventing the peer from writing bytes on the wire. The attacker then sends a stream of requests for a large response object, which can consume excess memory, CPU, or both, depending on how servers queue responses.
Recommendations For Apache Traffic Server, update to a version that includes a fix for the HTTP/2 implementation issue. For Apache HTTP Server, consider disabling the HTTP/2 protocol until a patch is available. For Node.js, restrict access to the HTTP/2 module to minimize the risk of exploitation. As a temporary workaround, consider limiting the size of response objects to prevent excessive memory or CPU consumption. Avoid using the HTTP/2 protocol in affected versions until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Resource Exhaustion

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2019:2925
ALT-PU-2019-2471
ALT-PU-2019-3050
ALT-PU-2019-3402
ALT-PU-2020-2195
BDU:2019-03647
BDU:2019-03780
CESA-2019_2893
CESA-2019_2925
CLEANSTART-2026-BD71263
CLEANSTART-2026-IS74202
CLEANSTART-2026-JR35772
CLEANSTART-2026-JY06700
CLEANSTART-2026-KN34553
CLEANSTART-2026-KZ45320
CLEANSTART-2026-LJ44720
CLEANSTART-2026-LN12820
CLEANSTART-2026-TX00223
CLEANSTART-2026-WI75198
CVE-2019-9517
DSA-4509-1
DSA-4509-2
MGASA-2019-0407
MGASA-2020-0372
OPENSUSE-SU-2019:2051-1
OPENSUSE-SU-2019:2114-1
OPENSUSE-SU-2019:2115-1
OPENSUSE-SU-2019_2051-1
OPENSUSE-SU-2019_2114-1
OPENSUSE-SU-2019_2115-1
OPENSUSE-SU-2024:10623-1
RHSA-2019:2893
RHSA-2019:2925
RHSA-2019:2939
RHSA-2019:2946
RHSA-2019:2949
RHSA-2019:2955
RHSA-2019:3932
RHSA-2019:3933
RHSA-2019_2893
RHSA-2019_2925
RLSA-2019:2925
SUSE-SU-2019:14246-1
SUSE-SU-2019:2237-1
SUSE-SU-2019:2254-1
SUSE-SU-2019:2259-1
SUSE-SU-2019:2260-1
SUSE-SU-2019:2329-1
SUSE-SU-2019_14246-1
SUSE-SU-2020:0059-1
USN-4113-1
USN-4113-2

Affected Products

Alt Linux
Almalinux
Apache Http Server
Apache Traffic Server
Centos
Node.Js
Red Hat
Rocky Linux
Suse
Ubuntu