Some HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of service
Published Aug 13, 2019
6.5
MEDIUMCVSS 3.1
EPSS 56.26%
Description
Some HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of service. The attacker sends a stream of headers with a 0-length header name and 0-length header value, optionally Huffman encoded into 1-byte or greater headers. Some implementations allocate memory for these headers and keep the allocation alive until the session dies. This can consume excess memory.
Affected products
No data.
Configuration 1
Configuration 2
- ≥ 6.0.0 · ≤ 6.2.3
- ≥ 7.0.0 · ≤ 7.1.6
- ≥ 8.0.0 · ≤ 8.0.3
Configuration 3
- 16.04
- 18.04
- 19.04
Configuration 4
- 9.0
- 10.0
- 30
Configuration 5
- n/a
- 6.2
Configuration 6
- n/a
Configuration 7
- 9.0
- 10.0
Configuration 8
- 29
- 30
- 32
Configuration 10
- 1.0
- 7.2.0
- 7.3.0
- 1.0
- 3.0.0
- 1.0
- 8.0
Configuration 12
- ≥ 7.7.2.0 · < 7.7.2.24
- ≥ 7.8.2.0 · < 7.8.2.13
- ≥ 8.1.0 · < 8.2.0
Configuration 13
No data.
JBoss Core Services on RHEL 6
jbcs-httpd24-apr-0:1.6.3-63.jbcs.el6
Fixed · RHSA-2019:3932
JBoss Core Services on RHEL 6
jbcs-httpd24-apr-util-0:1.6.1-48.jbcs.el6
Fixed · RHSA-2019:3932
JBoss Core Services on RHEL 6
jbcs-httpd24-brotli-0:1.0.6-7.jbcs.el6
Fixed · RHSA-2019:3932
JBoss Core Services on RHEL 6
jbcs-httpd24-curl-0:7.64.1-14.jbcs.el6
Fixed · RHSA-2019:3932
JBoss Core Services on RHEL 6
jbcs-httpd24-httpd-0:2.4.29-41.jbcs.el6
Fixed · RHSA-2019:2946
JBoss Core Services on RHEL 6
jbcs-httpd24-httpd-0:2.4.37-33.jbcs.el6
Fixed · RHSA-2019:3932
JBoss Core Services on RHEL 6
jbcs-httpd24-jansson-0:2.11-20.jbcs.el6
Fixed · RHSA-2019:3932
JBoss Core Services on RHEL 6
jbcs-httpd24-mod_cluster-native-0:1.3.12-9.Final_redhat_2.jbcs.el6
Fixed · RHSA-2019:3932
JBoss Core Services on RHEL 6
jbcs-httpd24-mod_jk-0:1.2.46-22.redhat_1.jbcs.el6
Fixed · RHSA-2019:3932
JBoss Core Services on RHEL 6
jbcs-httpd24-mod_security-0:2.9.2-16.GA.jbcs.el6
Fixed · RHSA-2019:3932
JBoss Core Services on RHEL 6
jbcs-httpd24-nghttp2-0:1.39.2-1.jbcs.el6
Fixed · RHSA-2019:2946
JBoss Core Services on RHEL 6
jbcs-httpd24-nghttp2-0:1.39.2-4.jbcs.el6
Fixed · RHSA-2019:3932
JBoss Core Services on RHEL 6
jbcs-httpd24-openssl-1:1.1.1-25.jbcs.el6
Fixed · RHSA-2019:3932
JBoss Core Services on RHEL 7
jbcs-httpd24-apr-0:1.6.3-63.jbcs.el7
Fixed · RHSA-2019:3933
JBoss Core Services on RHEL 7
jbcs-httpd24-apr-util-0:1.6.1-48.jbcs.el7
Fixed · RHSA-2019:3933
JBoss Core Services on RHEL 7
jbcs-httpd24-brotli-0:1.0.6-7.jbcs.el7
Fixed · RHSA-2019:3933
JBoss Core Services on RHEL 7
jbcs-httpd24-curl-0:7.64.1-14.jbcs.el7
Fixed · RHSA-2019:3933
JBoss Core Services on RHEL 7
jbcs-httpd24-httpd-0:2.4.29-41.jbcs.el7
Fixed · RHSA-2019:2946
JBoss Core Services on RHEL 7
jbcs-httpd24-httpd-0:2.4.37-33.jbcs.el7
Fixed · RHSA-2019:3933
JBoss Core Services on RHEL 7
jbcs-httpd24-jansson-0:2.11-20.jbcs.el7
Fixed · RHSA-2019:3933
JBoss Core Services on RHEL 7
jbcs-httpd24-mod_cluster-native-0:1.3.12-9.Final_redhat_2.jbcs.el7
Fixed · RHSA-2019:3933
JBoss Core Services on RHEL 7
jbcs-httpd24-mod_jk-0:1.2.46-22.redhat_1.jbcs.el7
Fixed · RHSA-2019:3933
JBoss Core Services on RHEL 7
jbcs-httpd24-mod_security-0:2.9.2-16.GA.jbcs.el7
Fixed · RHSA-2019:3933
JBoss Core Services on RHEL 7
jbcs-httpd24-nghttp2-0:1.39.2-1.jbcs.el7
Fixed · RHSA-2019:2946
JBoss Core Services on RHEL 7
jbcs-httpd24-nghttp2-0:1.39.2-4.jbcs.el7
Fixed · RHSA-2019:3933
JBoss Core Services on RHEL 7
jbcs-httpd24-openssl-1:1.1.1-25.jbcs.el7
Fixed · RHSA-2019:3933
Red Hat AMQ
n/a
Fixed · RHSA-2020:0922
Red Hat AMQ 7.4.3
n/a
Fixed · RHSA-2020:1445
Red Hat Enterprise Linux 8
nginx:1.14-8000020190830002848.f8e95b4e
Fixed · RHSA-2019:2799
Red Hat Enterprise Linux 8
nodejs:10-8000020190911085529.f8e95b4e
Fixed · RHSA-2019:2925
Red Hat Fuse 7.6.0
undertow
Fixed · RHSA-2020:0983
Red Hat JBoss Core Services
n/a
Fixed · RHSA-2019:3935
Red Hat JBoss Core Services
mod_http2
Fixed · RHSA-2019:2950
Red Hat Quay 3
quay3/clair-jwt:v2.0.9-7
Fixed · RHSA-2019:2966
Red Hat Software Collections for Red Hat Enterprise Linux 6
rh-nginx110-nginx-1:1.10.2-9.el6.1
Fixed · RHSA-2019:2745
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-nginx110-nginx-1:1.10.2-9.el7.1
Fixed · RHSA-2019:2745
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-nginx112-nginx-1:1.12.1-3.el7.1
Fixed · RHSA-2019:2746
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-nginx114-nginx-1:1.14.1-1.el7.1
Fixed · RHSA-2019:2775
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-nodejs10-0:3.2-3.el7
Fixed · RHSA-2019:2939
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-nodejs10-nodejs-0:10.16.3-3.el7
Fixed · RHSA-2019:2939
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-nodejs8-0:3.0-5.el7
Fixed · RHSA-2019:2955
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-nodejs8-nodejs-0:8.16.1-2.el7
Fixed · RHSA-2019:2955
Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS
rh-nginx110-nginx-1:1.10.2-9.el7.1
Fixed · RHSA-2019:2745
Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS
rh-nginx112-nginx-1:1.12.1-3.el7.1
Fixed · RHSA-2019:2746
Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS
rh-nginx114-nginx-1:1.14.1-1.el7.1
Fixed · RHSA-2019:2775
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS
rh-nginx110-nginx-1:1.10.2-9.el7.1
Fixed · RHSA-2019:2745
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS
rh-nginx112-nginx-1:1.12.1-3.el7.1
Fixed · RHSA-2019:2746
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS
rh-nginx114-nginx-1:1.14.1-1.el7.1
Fixed · RHSA-2019:2775
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS
rh-nodejs10-0:3.2-3.el7
Fixed · RHSA-2019:2939
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS
rh-nodejs10-nodejs-0:10.16.3-3.el7
Fixed · RHSA-2019:2939
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS
rh-nodejs8-0:3.0-5.el7
Fixed · RHSA-2019:2955
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS
rh-nodejs8-nodejs-0:8.16.1-2.el7
Fixed · RHSA-2019:2955
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS
rh-nginx110-nginx-1:1.10.2-9.el7.1
Fixed · RHSA-2019:2745
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS
rh-nginx112-nginx-1:1.12.1-3.el7.1
Fixed · RHSA-2019:2746
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS
rh-nginx114-nginx-1:1.14.1-1.el7.1
Fixed · RHSA-2019:2775
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS
rh-nodejs10-0:3.2-3.el7
Fixed · RHSA-2019:2939
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS
rh-nodejs10-nodejs-0:10.16.3-3.el7
Fixed · RHSA-2019:2939
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS
rh-nodejs8-0:3.0-5.el7
Fixed · RHSA-2019:2955
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS
rh-nodejs8-nodejs-0:8.16.1-2.el7
Fixed · RHSA-2019:2955
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS
rh-nginx110-nginx-1:1.10.2-9.el7.1
Fixed · RHSA-2019:2745
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS
rh-nginx112-nginx-1:1.12.1-3.el7.1
Fixed · RHSA-2019:2746
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS
rh-nginx114-nginx-1:1.14.1-1.el7.1
Fixed · RHSA-2019:2775
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS
rh-nodejs10-0:3.2-3.el7
Fixed · RHSA-2019:2939
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS
rh-nodejs10-nodejs-0:10.16.3-3.el7
Fixed · RHSA-2019:2939
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS
rh-nodejs8-0:3.0-5.el7
Fixed · RHSA-2019:2955
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS
rh-nodejs8-nodejs-0:8.16.1-2.el7
Fixed · RHSA-2019:2955
CloudForms Management Engine 5
nginx
Not affected
Red Hat 3scale API Management Platform 2
nginx
Affected
Red Hat AMQ Broker 7
jetty
Affected
Red Hat AMQ Broker 7
netty
Not affected
Red Hat Ansible Tower 3
nginx
Not affected
Red Hat Enterprise Linux 8
httpd:2.4/mod_http2
Not affected
Red Hat Enterprise Linux 8
nghttp2
Not affected
Red Hat Enterprise Linux 8
nginx:1.16/nginx
Not affected
Red Hat JBoss Data Grid 7
undertow
Not affected
Red Hat JBoss Enterprise Application Platform 6
jbossweb
Not affected
Red Hat JBoss Enterprise Application Platform 7
undertow-core
Not affected
Red Hat JBoss Enterprise Web Server 3
httpd
Out of support scope
Red Hat JBoss Fuse 6
undertow
Out of support scope
Red Hat JBoss Web Server 5
nghttp2
Not affected
Red Hat OpenShift Application Runtimes
rhoar-nodejs
Out of support scope
Red Hat OpenShift Application Runtimes
undertow
Not affected
Red Hat OpenShift Container Platform 3.10
atomic-openshift
Not affected
Red Hat OpenShift Container Platform 3.10
nodejs
Not affected
Red Hat OpenShift Container Platform 3.11
atomic-openshift
Not affected
Red Hat OpenShift Container Platform 3.9
atomic-openshift
Not affected
Red Hat OpenShift Container Platform 3.9
nodejs
Not affected
Red Hat OpenShift Container Platform 4
openshift
Not affected
Red Hat Process Automation 7
undertow
Not affected
Red Hat Quay 3
nodejs
Not affected
Red Hat Single Sign-On 7
undertow
Not affected
Red Hat Software Collections
httpd24-httpd
Not affected
Red Hat Software Collections
httpd24-nghttp2
Not affected
Red Hat Software Collections
rh-nginx116-nginx
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| JBoss Core Services on RHEL 6 | jbcs-httpd24-apr-0:1.6.3-63.jbcs.el6 | Fixed | RHSA-2019:3932 |
| JBoss Core Services on RHEL 6 | jbcs-httpd24-apr-util-0:1.6.1-48.jbcs.el6 | Fixed | RHSA-2019:3932 |
| JBoss Core Services on RHEL 6 | jbcs-httpd24-brotli-0:1.0.6-7.jbcs.el6 | Fixed | RHSA-2019:3932 |
| JBoss Core Services on RHEL 6 | jbcs-httpd24-curl-0:7.64.1-14.jbcs.el6 | Fixed | RHSA-2019:3932 |
| JBoss Core Services on RHEL 6 | jbcs-httpd24-httpd-0:2.4.29-41.jbcs.el6 | Fixed | RHSA-2019:2946 |
| JBoss Core Services on RHEL 6 | jbcs-httpd24-httpd-0:2.4.37-33.jbcs.el6 | Fixed | RHSA-2019:3932 |
| JBoss Core Services on RHEL 6 | jbcs-httpd24-jansson-0:2.11-20.jbcs.el6 | Fixed | RHSA-2019:3932 |
| JBoss Core Services on RHEL 6 | jbcs-httpd24-mod_cluster-native-0:1.3.12-9.Final_redhat_2.jbcs.el6 | Fixed | RHSA-2019:3932 |
| JBoss Core Services on RHEL 6 | jbcs-httpd24-mod_jk-0:1.2.46-22.redhat_1.jbcs.el6 | Fixed | RHSA-2019:3932 |
| JBoss Core Services on RHEL 6 | jbcs-httpd24-mod_security-0:2.9.2-16.GA.jbcs.el6 | Fixed | RHSA-2019:3932 |
| JBoss Core Services on RHEL 6 | jbcs-httpd24-nghttp2-0:1.39.2-1.jbcs.el6 | Fixed | RHSA-2019:2946 |
| JBoss Core Services on RHEL 6 | jbcs-httpd24-nghttp2-0:1.39.2-4.jbcs.el6 | Fixed | RHSA-2019:3932 |
| JBoss Core Services on RHEL 6 | jbcs-httpd24-openssl-1:1.1.1-25.jbcs.el6 | Fixed | RHSA-2019:3932 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-apr-0:1.6.3-63.jbcs.el7 | Fixed | RHSA-2019:3933 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-apr-util-0:1.6.1-48.jbcs.el7 | Fixed | RHSA-2019:3933 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-brotli-0:1.0.6-7.jbcs.el7 | Fixed | RHSA-2019:3933 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-curl-0:7.64.1-14.jbcs.el7 | Fixed | RHSA-2019:3933 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-httpd-0:2.4.29-41.jbcs.el7 | Fixed | RHSA-2019:2946 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-httpd-0:2.4.37-33.jbcs.el7 | Fixed | RHSA-2019:3933 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-jansson-0:2.11-20.jbcs.el7 | Fixed | RHSA-2019:3933 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-mod_cluster-native-0:1.3.12-9.Final_redhat_2.jbcs.el7 | Fixed | RHSA-2019:3933 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-mod_jk-0:1.2.46-22.redhat_1.jbcs.el7 | Fixed | RHSA-2019:3933 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-mod_security-0:2.9.2-16.GA.jbcs.el7 | Fixed | RHSA-2019:3933 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-nghttp2-0:1.39.2-1.jbcs.el7 | Fixed | RHSA-2019:2946 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-nghttp2-0:1.39.2-4.jbcs.el7 | Fixed | RHSA-2019:3933 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-openssl-1:1.1.1-25.jbcs.el7 | Fixed | RHSA-2019:3933 |
| Red Hat AMQ | n/a | Fixed | RHSA-2020:0922 |
| Red Hat AMQ 7.4.3 | n/a | Fixed | RHSA-2020:1445 |
| Red Hat Enterprise Linux 8 | nginx:1.14-8000020190830002848.f8e95b4e | Fixed | RHSA-2019:2799 |
| Red Hat Enterprise Linux 8 | nodejs:10-8000020190911085529.f8e95b4e | Fixed | RHSA-2019:2925 |
| Red Hat Fuse 7.6.0 | undertow | Fixed | RHSA-2020:0983 |
| Red Hat JBoss Core Services | n/a | Fixed | RHSA-2019:3935 |
| Red Hat JBoss Core Services | mod_http2 | Fixed | RHSA-2019:2950 |
| Red Hat Quay 3 | quay3/clair-jwt:v2.0.9-7 | Fixed | RHSA-2019:2966 |
| Red Hat Software Collections for Red Hat Enterprise Linux 6 | rh-nginx110-nginx-1:1.10.2-9.el6.1 | Fixed | RHSA-2019:2745 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-nginx110-nginx-1:1.10.2-9.el7.1 | Fixed | RHSA-2019:2745 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-nginx112-nginx-1:1.12.1-3.el7.1 | Fixed | RHSA-2019:2746 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-nginx114-nginx-1:1.14.1-1.el7.1 | Fixed | RHSA-2019:2775 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-nodejs10-0:3.2-3.el7 | Fixed | RHSA-2019:2939 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-nodejs10-nodejs-0:10.16.3-3.el7 | Fixed | RHSA-2019:2939 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-nodejs8-0:3.0-5.el7 | Fixed | RHSA-2019:2955 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-nodejs8-nodejs-0:8.16.1-2.el7 | Fixed | RHSA-2019:2955 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS | rh-nginx110-nginx-1:1.10.2-9.el7.1 | Fixed | RHSA-2019:2745 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS | rh-nginx112-nginx-1:1.12.1-3.el7.1 | Fixed | RHSA-2019:2746 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS | rh-nginx114-nginx-1:1.14.1-1.el7.1 | Fixed | RHSA-2019:2775 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS | rh-nginx110-nginx-1:1.10.2-9.el7.1 | Fixed | RHSA-2019:2745 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS | rh-nginx112-nginx-1:1.12.1-3.el7.1 | Fixed | RHSA-2019:2746 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS | rh-nginx114-nginx-1:1.14.1-1.el7.1 | Fixed | RHSA-2019:2775 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS | rh-nodejs10-0:3.2-3.el7 | Fixed | RHSA-2019:2939 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS | rh-nodejs10-nodejs-0:10.16.3-3.el7 | Fixed | RHSA-2019:2939 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS | rh-nodejs8-0:3.0-5.el7 | Fixed | RHSA-2019:2955 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS | rh-nodejs8-nodejs-0:8.16.1-2.el7 | Fixed | RHSA-2019:2955 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | rh-nginx110-nginx-1:1.10.2-9.el7.1 | Fixed | RHSA-2019:2745 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | rh-nginx112-nginx-1:1.12.1-3.el7.1 | Fixed | RHSA-2019:2746 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | rh-nginx114-nginx-1:1.14.1-1.el7.1 | Fixed | RHSA-2019:2775 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | rh-nodejs10-0:3.2-3.el7 | Fixed | RHSA-2019:2939 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | rh-nodejs10-nodejs-0:10.16.3-3.el7 | Fixed | RHSA-2019:2939 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | rh-nodejs8-0:3.0-5.el7 | Fixed | RHSA-2019:2955 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | rh-nodejs8-nodejs-0:8.16.1-2.el7 | Fixed | RHSA-2019:2955 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | rh-nginx110-nginx-1:1.10.2-9.el7.1 | Fixed | RHSA-2019:2745 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | rh-nginx112-nginx-1:1.12.1-3.el7.1 | Fixed | RHSA-2019:2746 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | rh-nginx114-nginx-1:1.14.1-1.el7.1 | Fixed | RHSA-2019:2775 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | rh-nodejs10-0:3.2-3.el7 | Fixed | RHSA-2019:2939 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | rh-nodejs10-nodejs-0:10.16.3-3.el7 | Fixed | RHSA-2019:2939 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | rh-nodejs8-0:3.0-5.el7 | Fixed | RHSA-2019:2955 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | rh-nodejs8-nodejs-0:8.16.1-2.el7 | Fixed | RHSA-2019:2955 |
| CloudForms Management Engine 5 | nginx | Not affected | n/a |
| Red Hat 3scale API Management Platform 2 | nginx | Affected | n/a |
| Red Hat AMQ Broker 7 | jetty | Affected | n/a |
| Red Hat AMQ Broker 7 | netty | Not affected | n/a |
| Red Hat Ansible Tower 3 | nginx | Not affected | n/a |
| Red Hat Enterprise Linux 8 | httpd:2.4/mod_http2 | Not affected | n/a |
| Red Hat Enterprise Linux 8 | nghttp2 | Not affected | n/a |
| Red Hat Enterprise Linux 8 | nginx:1.16/nginx | Not affected | n/a |
| Red Hat JBoss Data Grid 7 | undertow | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | jbossweb | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | undertow-core | Not affected | n/a |
| Red Hat JBoss Enterprise Web Server 3 | httpd | Out of support scope | n/a |
| Red Hat JBoss Fuse 6 | undertow | Out of support scope | n/a |
| Red Hat JBoss Web Server 5 | nghttp2 | Not affected | n/a |
| Red Hat OpenShift Application Runtimes | rhoar-nodejs | Out of support scope | n/a |
| Red Hat OpenShift Application Runtimes | undertow | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.10 | atomic-openshift | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.10 | nodejs | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.11 | atomic-openshift | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.9 | atomic-openshift | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.9 | nodejs | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift | Not affected | n/a |
| Red Hat Process Automation 7 | undertow | Not affected | n/a |
| Red Hat Quay 3 | nodejs | Not affected | n/a |
| Red Hat Single Sign-On 7 | undertow | Not affected | n/a |
| Red Hat Software Collections | httpd24-httpd | Not affected | n/a |
| Red Hat Software Collections | httpd24-nghttp2 | Not affected | n/a |
| Red Hat Software Collections | rh-nginx116-nginx | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This flaw has no available mitigation for nodejs package. It will be updated once the available fixes are released for Red Hat Enterprise Linux and Red Hat Software Collections. The nodejs RPM shipped in OpenShift Container Platform 3.9 and 3.10 is not affected by this flaw as it does not contain the vulnerable code.
Red Hat mitigation
Red Hat Quay 3.0 uses Nginx 1.12 from Red Hat Software Collections. It will be updated once a fixed is released for Software Collections. In the meantime users of Quay can disable http/2 support in Nginx by following these instructions: 1. Copy the Nginx configuration from the quay container to the host $ docker cp 3aadf1421ba3:/quay-registry/conf/nginx/ /mnt/quay/nginx 2. Edit the Nginx configuration, removing http/2 support $ sed -i 's/http2 //g' /mnt/quay/nginx/nginx.conf 3. Restart Nginx with the new configuration mounted into the container, eg: $ docker run --restart=always -p 443:8443 -p 80:8080 --sysctl net.core.somaxconn=4096 -v /mnt/quay/config:/conf/stack:Z -v /mnt/quay/storage:/datastorage -v /mnt/quay/nginx:/quay-registry/config/nginx:Z -d quay.io/redhat/quay:v3.0.3
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
1 other source (Red Hat) ▾
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
AV:N/AC:L/Au:S/C:N/I:N/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (40 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 56.26% (0.56262) | 99.03th | v5 (v2026.06.15) |
| Jun 27, 2026 | 56.26% (0.56262) | 98.93th | v5 (v2026.06.15) |
| Jun 15, 2026 | 57.46% (0.57461) | 98.95th | v5 (v2026.06.15) |
| Mar 4, 2026 | 2.39% (0.02393) | 84.77th | v4 (v2025.03.14) |
| Mar 1, 2026 | 3.92% (0.03917) | 88.12th | v4 (v2025.03.14) |
| Feb 4, 2026 | 2.39% (0.02393) | 84.67th | v4 (v2025.03.14) |
| Feb 1, 2026 | 3.92% (0.03917) | 88.06th | v4 (v2025.03.14) |
| Jan 4, 2026 | 2.39% (0.02393) | 84.60th | v4 (v2025.03.14) |
| Jan 1, 2026 | 3.92% (0.03917) | 88.01th | v4 (v2025.03.14) |
| Dec 4, 2025 | 2.39% (0.02393) | 84.53th | v4 (v2025.03.14) |
| Dec 1, 2025 | 3.92% (0.03917) | 87.92th | v4 (v2025.03.14) |
| Nov 21, 2025 | 2.17% (0.02173) | 83.80th | v4 (v2025.03.14) |
| Nov 18, 2025 | 24.17% (0.24170) | 95.71th | v4 (v2025.03.14) |
| Nov 4, 2025 | 2.29% (0.02287) | 84.14th | v4 (v2025.03.14) |
| Nov 1, 2025 | 3.75% (0.03747) | 87.57th | v4 (v2025.03.14) |
| Oct 4, 2025 | 2.29% (0.02287) | 84.12th | v4 (v2025.03.14) |
| Aug 1, 2025 | 3.29% (0.03292) | 86.81th | v4 (v2025.03.14) |
| Jul 4, 2025 | 2.21% (0.02211) | 83.77th | v4 (v2025.03.14) |
| Jul 1, 2025 | 3.62% (0.03625) | 87.38th | v4 (v2025.03.14) |
| Jun 4, 2025 | 2.21% (0.02211) | 83.66th | v4 (v2025.03.14) |
| Jun 1, 2025 | 3.62% (0.03625) | 87.30th | v4 (v2025.03.14) |
| Mar 30, 2025 | 1.97% (0.01969) | 81.90th | v4 (v2025.03.14) |
| Mar 29, 2025 | 3.10% (0.03101) | 77.90th | v4 (v2025.03.14) |
| Mar 17, 2025 | 1.97% (0.01969) | 82.33th | v4 (v2025.03.14) |
| Dec 17, 2024 | 2.34% (0.02338) | 89.45th | v3 (v2023.03.01) |
| Dec 12, 2024 | 0.70% (0.00702) | 80.97th | v3 (v2023.03.01) |
| Mar 8, 2024 | 0.66% (0.00663) | 79.14th | v3 (v2023.03.01) |
| Feb 9, 2024 | 0.71% (0.00706) | 79.75th | v3 (v2023.03.01) |
| Nov 22, 2023 | 0.65% (0.00650) | 77.11th | v3 (v2023.03.01) |
| Nov 8, 2023 | 0.72% (0.00723) | 78.41th | v3 (v2023.03.01) |
| Jul 4, 2023 | 0.32% (0.00321) | 66.48th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.28% (0.00279) | 63.36th | v3 (v2023.03.01) |
| Mar 6, 2023 | 3.05% (0.03052) | 83.71th | v2 (v2022.01.01) |
| Apr 1, 2022 | 3.05% (0.03052) | 82.04th | v2 (v2022.01.01) |
| Feb 23, 2022 | 37.22% (0.37224) | 97.11th | v2 (v2022.01.01) |
| Feb 4, 2022 | 27.57% (0.27569) | 95.91th | v2 (v2022.01.01) |
| Feb 3, 2022 | 16.63% (0.16627) | 90.26th | v1 |
| Jan 6, 2022 | 16.63% (0.16627) | 90.14th | v1 |
| Sep 1, 2021 | 4.26% (0.04256) | 83.49th | v1 |
| Apr 14, 2021 | 4.26% (0.04256) | 0.00th | v1 |
References (44)
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00031.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00032.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00035.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00014.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2019/Aug/16 mailing-listx_refsource_FULLDISCMailing ListThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2745 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2746 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2775 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2799 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2925 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2939 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2946 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2950 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2955 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2966 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3932 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3933 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3935 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-9516 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1741864 Issue Tracking
- https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-002.md x_refsource_MISCThird Party Advisory
- https://github.com/nghttp2/nghttp2/issues/1382#
- https://kb.cert.org/vuls/id/605641/ third-party-advisoryx_refsource_CERT-VNThird Party AdvisoryUS Government Resource
- https://kc.mcafee.com/corporate/index?page=content&id=SB10296 x_refsource_CONFIRMThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4ZQGHE3WTYLYAYJEIDJVF2FIGQTAYPMC/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BP556LEG3WENHZI5TAQ6ZEBFTJB4E2IS/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CMNFX5MNYRWWIMO4BTKYQCGUDMHO3AXP/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H472D5HPXN6RRXCNFML3BK5OYC52CXF2/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/POPAEC4FWL4UU4LDEGPY5NPALU24FFQD/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TAZZEVTCN2B4WT6AIBJ7XGYJMBTORJU5/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XHTKU7YQ5EEP2XNSAV4M4VJ7QCBOJMOD/ vendor-advisoryx_refsource_FEDORA
- https://nodejs.org/en/blog/vulnerability/aug-2019-security-releases/
- https://nvd.nist.gov/vuln/detail/CVE-2019-9516
- https://seclists.org/bugtraq/2019/Aug/24 mailing-listx_refsource_BUGTRAQMailing ListThird Party Advisory
- https://seclists.org/bugtraq/2019/Aug/40 mailing-listx_refsource_BUGTRAQMailing ListThird Party Advisory
- https://security.netapp.com/advisory/ntap-20190823-0002/ x_refsource_CONFIRMThird Party Advisory
- https://security.netapp.com/advisory/ntap-20190823-0005/ x_refsource_CONFIRMThird Party Advisory
- https://support.f5.com/csp/article/K02591030 x_refsource_CONFIRMThird Party Advisory
- https://support.f5.com/csp/article/K02591030?utm_source=f5support&%3Butm_medium=RSS x_refsource_CONFIRM
- https://usn.ubuntu.com/4099-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-9516
- https://www.debian.org/security/2019/dsa-4505 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- https://www.nginx.com/blog/nginx-updates-mitigate-august-2019-http-2-vulnerabilities/
- https://www.synology.com/security/advisory/Synology_SA_19_33 x_refsource_CONFIRMThird Party Advisory
Change history (0)
No recorded changes yet.