CVE-2019-9518: Some HTTP/2 implementations are vulnerable to a flood of empty frames, potentially leading to a denial of service
A flaw was found in HTTP/2. Using frames with an empty payload, a flood could occur that results in excessive CPU usage and starvation of other clients. The highest threat from this vulnerability is to system availability.
Other sources
HTTP/2 flood using frames with an empty payload that results in excessive CPU usage and starvation of other clients.
— Red Hat
Some HTTP/2 implementations are vulnerable to a flood of empty frames, potentially leading to a denial of service. The attacker sends a stream of frames with an empty payload and without the end-of-stream flag. These frames can be DATA, HEADERS, CONTINUATION and/or PUSHPROMISE. The peer spends time processing each frame disproportionate to attack bandwidth. This can consume excess CPU.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2019-9518?
CVE-2019-9518 is a vulnerability in HTTP/2 that allows for a flood of empty frames, potentially leading to a denial of service.
What is the severity of CVE-2019-9518?
CVE-2019-9518 has a severity level of high, with a severity value of 7.
Which software is affected by CVE-2019-9518?
The affected software includes rh-nodejs10, rh-nodejs10-nodejs, rh-nodejs8, rh-nodejs8-nodejs, envoy, Nodejs, undertow, netty, and trafficserver.
How can CVE-2019-9518 be fixed?
To fix CVE-2019-9518, ensure that you have the latest versions of the affected software installed, as specified in the Remediation section of the references.
Where can I find more information about CVE-2019-9518?
You can find more information about CVE-2019-9518 in the references provided.