CVE-2019-9512

Source
https://cve.org/CVERecord?id=CVE-2019-9512
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-9512.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2019-9512
Aliases
Downstream
ALPINE (1)
AZL (1)
BELL (1)
CGA (8)
CLEANSTART (13)
DEBIAN (1)
MGASA (3)
openSUSE (12)
RHBA (2)
RHSA (24)
RLSA (3)
SUSE (7)
UBUNTU (1)
Related
Published
2019-08-13T21:15:12Z
Modified
2026-07-17T21:01:55Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

Some HTTP/2 implementations are vulnerable to ping floods, potentially leading to a denial of service. The attacker sends continual pings to an HTTP/2 peer, causing the peer to build an internal queue of responses. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both.

Database specific
{
    "unresolved_ranges":  [
        {
            "cpes":  [
                "cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:*",
                "cpe:2.3:a:nodejs:node.js:*:*:*:*:lts:*:*:*"
            ],
            "extracted_events":  [
                {
                    "introduced":  "8.0.0"
                },
                {
                    "last_affected":  "8.8.1"
                },
                {
                    "introduced":  "8.9.0"
                },
                {
                    "fixed":  "8.16.1"
                },
                {
                    "introduced":  "10.0.0"
                },
                {
                    "last_affected":  "10.12.0"
                },
                {
                    "introduced":  "10.13.0"
                },
                {
                    "fixed":  "10.16.3"
                },
                {
                    "introduced":  "12.0.0"
                },
                {
                    "fixed":  "12.8.1"
                }
            ],
            "source":  "CPE_RANGE",
            "vendor_product":  "nodejs:node.js"
        },
        {
            "cpes":  [
                "cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*"
            ],
            "extracted_events":  [
                {
                    "introduced":  "10.0"
                },
                {
                    "last_affected":  "10.0"
                }
            ],
            "source":  "CPE_STRING",
            "vendor_product":  "debian:debian_linux"
        }
    ]
}
References

Affected packages

Git / github.com/apache/trafficserver

Affected ranges

Type
GIT
Repo
https://github.com/apache/trafficserver
Events
Database specific
Show details
{
    "cpe":  "cpe:2.3:a:apache:traffic_server:*:*:*:*:*:*:*:*",
    "extracted_events":  [
        {
            "introduced":  "6.0.0"
        },
        {
            "last_affected":  "6.2.3"
        },
        {
            "introduced":  "7.0.0"
        },
        {
            "last_affected":  "7.1.6"
        },
        {
            "introduced":  "8.0.0"
        },
        {
            "last_affected":  "8.0.3"
        }
    ],
    "source":  "CPE_RANGE"
}

Affected versions

8.*
8.0.0
8.0.0-rc4
8.0.1
8.0.1-rc0
8.0.2
8.0.2-rc0
8.0.3
8.0.3-rc0

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-9512.json"

Git / github.com/apple/swift-nio

Affected ranges

Type
GIT
Repo
https://github.com/apple/swift-nio
Events
Database specific
Show details
{
    "cpe":  "cpe:2.3:a:apple:swiftnio:*:*:*:*:*:*:*:*",
    "extracted_events":  [
        {
            "introduced":  "1.0.0"
        },
        {
            "last_affected":  "1.4.0"
        }
    ],
    "source":  "CPE_RANGE"
}

Affected versions

1.*
1.0.0
1.1.0
1.2.0
1.2.1
1.3.0
1.3.1
1.4.0

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-9512.json"