cbcvebase.
CVE-2019-9516
published 2019-08-13

CVE-2019-9516: Some HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of service. The attacker sends a stream of headers with a 0-length…

PriorityP346medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
56.26%
99.0th percentile
Some HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of service. The attacker sends a stream of headers with a 0-length header name and 0-length header value, optionally Huffman encoded into 1-byte or greater headers. Some implementations allocate memory for these headers and keep the allocation alive until the session dies. This can consume excess memory.

Affected

40 ranges· showing 25
VendorProductVersion rangeFixed in
apachetraffic_server6.0.0 – 6.2.3
apachetraffic_server7.0.0 – 7.1.6
apachetraffic_server8.0.0 – 8.0.3
appleswiftnio1.0.0 – 1.4.0
appleswiftnio_http_2
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debiannginx< nginx 1.14.2-3 (bookworm)nginx 1.14.2-3 (bookworm)
f5nginx>= 0 < 1.14.2-31.14.2-3
f5nginx>= 0 < 1.14.2-31.14.2-3
f5nginx>= 0 < 1.14.2-31.14.2-3
f5nginx>= 0 < 1.14.2-31.14.2-3
f5nginx1.17.0 – 1.17.2
f5nginx>= 1.9.5 < 1.16.11.16.1
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
mcafeeweb_gateway>= 7.7.2.0 < 7.7.2.247.7.2.24
mcafeeweb_gateway>= 7.8.2.0 < 7.8.2.137.8.2.13
mcafeeweb_gateway>= 8.1.0 < 8.2.08.2.0
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64

Detection & IOCsextracted from sources · hover to see the quote

  • Detect HTTP/2 streams containing headers with 0-length header name and 0-length header value, optionally Huffman encoded, sent repeatedly to exhaust server memory
  • Monitor for unbounded memory growth on HTTP/2 servers correlating with sustained inbound connections; resource exhaustion is the primary observable impact
  • ·Disabling HTTP/2 support in nginx mitigates the vulnerability; Red Hat documents a sed-based procedure to strip 'http2' from nginx.conf as an interim workaround
  • ·nodejs package has no available mitigation and must await upstream fixes; the nodejs RPM in OpenShift Container Platform 3.9 and 3.10 is not affected as it does not contain the vulnerable code
  • ·SwiftNIO HTTP/2 1.5.0 addresses the issue via improved buffer size management; deployments should upgrade to this version or later
  • ·nginx (Debian) is fixed in version 1.14.2-3 across bookworm, bullseye, forky, sid, and trixie

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.06.8MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:C
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_msrc6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.