Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to a denial of service
Published Aug 13, 2019
7.5
HIGHCVSS 3.1
EPSS 27.89%
Description
Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to a denial of service. The attacker opens the HTTP/2 window so the peer can send without constraint; however, they leave the TCP window closed so the peer cannot actually write (many of) the bytes on the wire. The attacker then sends a stream of requests for a large response object. Depending on how the servers queue the responses, this can consume excess memory, CPU, or both.
Affected products
No data.
Configuration 1
Configuration 2
- ≥ 2.4.20 · < 2.4.40
- ≥ 6.0.0 · ≤ 6.2.3
- ≥ 7.0.0 · ≤ 7.1.6
- ≥ 8.0.0 · ≤ 8.0.3
Configuration 3
- 16.04
- 18.04
- 19.04
Configuration 4
- 9.0
- 10.0
Configuration 5
- n/a
- 6.2
Configuration 6
- n/a
Configuration 7
- 29
- 30
Configuration 9
- 1.0
- 7.2.0
- 7.3.0
- 1.0
- 3.0.0
- 1.0
- 8.0
Configuration 10
- 8.0.0
- 8.1.0
- 8.1.1
- 8.2.0
- 19.2.0
- ≥ 17.1 · ≤ 17.3
- 7.1
Configuration 11
- ≥ 7.7.2.0 · < 7.7.2.24
- ≥ 7.8.2.0 · < 7.8.2.13
- ≥ 8.1.0 · < 8.2.0
Configuration 12
- n/a
No data.
JBoss Core Services on RHEL 6
jbcs-httpd24-apr-0:1.6.3-63.jbcs.el6
Fixed · RHSA-2019:3932
JBoss Core Services on RHEL 6
jbcs-httpd24-apr-util-0:1.6.1-48.jbcs.el6
Fixed · RHSA-2019:3932
JBoss Core Services on RHEL 6
jbcs-httpd24-brotli-0:1.0.6-7.jbcs.el6
Fixed · RHSA-2019:3932
JBoss Core Services on RHEL 6
jbcs-httpd24-curl-0:7.64.1-14.jbcs.el6
Fixed · RHSA-2019:3932
JBoss Core Services on RHEL 6
jbcs-httpd24-httpd-0:2.4.29-41.jbcs.el6
Fixed · RHSA-2019:2946
JBoss Core Services on RHEL 6
jbcs-httpd24-httpd-0:2.4.37-33.jbcs.el6
Fixed · RHSA-2019:3932
JBoss Core Services on RHEL 6
jbcs-httpd24-jansson-0:2.11-20.jbcs.el6
Fixed · RHSA-2019:3932
JBoss Core Services on RHEL 6
jbcs-httpd24-mod_cluster-native-0:1.3.12-9.Final_redhat_2.jbcs.el6
Fixed · RHSA-2019:3932
JBoss Core Services on RHEL 6
jbcs-httpd24-mod_jk-0:1.2.46-22.redhat_1.jbcs.el6
Fixed · RHSA-2019:3932
JBoss Core Services on RHEL 6
jbcs-httpd24-mod_security-0:2.9.2-16.GA.jbcs.el6
Fixed · RHSA-2019:3932
JBoss Core Services on RHEL 6
jbcs-httpd24-nghttp2-0:1.39.2-1.jbcs.el6
Fixed · RHSA-2019:2946
JBoss Core Services on RHEL 6
jbcs-httpd24-nghttp2-0:1.39.2-4.jbcs.el6
Fixed · RHSA-2019:3932
JBoss Core Services on RHEL 6
jbcs-httpd24-openssl-1:1.1.1-25.jbcs.el6
Fixed · RHSA-2019:3932
JBoss Core Services on RHEL 7
jbcs-httpd24-apr-0:1.6.3-63.jbcs.el7
Fixed · RHSA-2019:3933
JBoss Core Services on RHEL 7
jbcs-httpd24-apr-util-0:1.6.1-48.jbcs.el7
Fixed · RHSA-2019:3933
JBoss Core Services on RHEL 7
jbcs-httpd24-brotli-0:1.0.6-7.jbcs.el7
Fixed · RHSA-2019:3933
JBoss Core Services on RHEL 7
jbcs-httpd24-curl-0:7.64.1-14.jbcs.el7
Fixed · RHSA-2019:3933
JBoss Core Services on RHEL 7
jbcs-httpd24-httpd-0:2.4.29-41.jbcs.el7
Fixed · RHSA-2019:2946
JBoss Core Services on RHEL 7
jbcs-httpd24-httpd-0:2.4.37-33.jbcs.el7
Fixed · RHSA-2019:3933
JBoss Core Services on RHEL 7
jbcs-httpd24-jansson-0:2.11-20.jbcs.el7
Fixed · RHSA-2019:3933
JBoss Core Services on RHEL 7
jbcs-httpd24-mod_cluster-native-0:1.3.12-9.Final_redhat_2.jbcs.el7
Fixed · RHSA-2019:3933
JBoss Core Services on RHEL 7
jbcs-httpd24-mod_jk-0:1.2.46-22.redhat_1.jbcs.el7
Fixed · RHSA-2019:3933
JBoss Core Services on RHEL 7
jbcs-httpd24-mod_security-0:2.9.2-16.GA.jbcs.el7
Fixed · RHSA-2019:3933
JBoss Core Services on RHEL 7
jbcs-httpd24-nghttp2-0:1.39.2-1.jbcs.el7
Fixed · RHSA-2019:2946
JBoss Core Services on RHEL 7
jbcs-httpd24-nghttp2-0:1.39.2-4.jbcs.el7
Fixed · RHSA-2019:3933
JBoss Core Services on RHEL 7
jbcs-httpd24-openssl-1:1.1.1-25.jbcs.el7
Fixed · RHSA-2019:3933
Red Hat AMQ
n/a
Fixed · RHSA-2020:0922
Red Hat AMQ 7.4.3
n/a
Fixed · RHSA-2020:1445
Red Hat Enterprise Linux 8
httpd:2.4-8000020190829150747.f8e95b4e
Fixed · RHSA-2019:2893
Red Hat Enterprise Linux 8
nodejs:10-8000020190911085529.f8e95b4e
Fixed · RHSA-2019:2925
Red Hat Fuse 7.6.0
undertow
Fixed · RHSA-2020:0983
Red Hat JBoss Core Services
n/a
Fixed · RHSA-2019:3935
Red Hat JBoss Core Services
mod_http2
Fixed · RHSA-2019:2950
Red Hat Software Collections for Red Hat Enterprise Linux 6
httpd24-httpd-0:2.4.34-8.el6.1
Fixed · RHSA-2019:2949
Red Hat Software Collections for Red Hat Enterprise Linux 6
httpd24-nghttp2-0:1.7.1-7.el6.1
Fixed · RHSA-2019:2949
Red Hat Software Collections for Red Hat Enterprise Linux 7
httpd24-httpd-0:2.4.34-8.el7.1
Fixed · RHSA-2019:2949
Red Hat Software Collections for Red Hat Enterprise Linux 7
httpd24-nghttp2-0:1.7.1-7.el7.1
Fixed · RHSA-2019:2949
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-nodejs10-0:3.2-3.el7
Fixed · RHSA-2019:2939
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-nodejs10-nodejs-0:10.16.3-3.el7
Fixed · RHSA-2019:2939
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-nodejs8-0:3.0-5.el7
Fixed · RHSA-2019:2955
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-nodejs8-nodejs-0:8.16.1-2.el7
Fixed · RHSA-2019:2955
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS
httpd24-httpd-0:2.4.34-8.el7.1
Fixed · RHSA-2019:2949
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS
httpd24-nghttp2-0:1.7.1-7.el7.1
Fixed · RHSA-2019:2949
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS
rh-nodejs10-0:3.2-3.el7
Fixed · RHSA-2019:2939
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS
rh-nodejs10-nodejs-0:10.16.3-3.el7
Fixed · RHSA-2019:2939
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS
rh-nodejs8-0:3.0-5.el7
Fixed · RHSA-2019:2955
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS
rh-nodejs8-nodejs-0:8.16.1-2.el7
Fixed · RHSA-2019:2955
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS
httpd24-httpd-0:2.4.34-8.el7.1
Fixed · RHSA-2019:2949
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS
httpd24-nghttp2-0:1.7.1-7.el7.1
Fixed · RHSA-2019:2949
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS
rh-nodejs10-0:3.2-3.el7
Fixed · RHSA-2019:2939
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS
rh-nodejs10-nodejs-0:10.16.3-3.el7
Fixed · RHSA-2019:2939
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS
rh-nodejs8-0:3.0-5.el7
Fixed · RHSA-2019:2955
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS
rh-nodejs8-nodejs-0:8.16.1-2.el7
Fixed · RHSA-2019:2955
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS
httpd24-httpd-0:2.4.34-8.el7.1
Fixed · RHSA-2019:2949
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS
httpd24-nghttp2-0:1.7.1-7.el7.1
Fixed · RHSA-2019:2949
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS
rh-nodejs10-0:3.2-3.el7
Fixed · RHSA-2019:2939
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS
rh-nodejs10-nodejs-0:10.16.3-3.el7
Fixed · RHSA-2019:2939
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS
rh-nodejs8-0:3.0-5.el7
Fixed · RHSA-2019:2955
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS
rh-nodejs8-nodejs-0:8.16.1-2.el7
Fixed · RHSA-2019:2955
CloudForms Management Engine 5
nginx
Not affected
Red Hat AMQ Broker 7
jetty
Affected
Red Hat Ansible Tower 3
nginx
Not affected
Red Hat Enterprise Linux 8
nghttp2
Not affected
Red Hat Enterprise Linux 8
nginx:1.14/nginx
Not affected
Red Hat JBoss Data Grid 7
undertow
Not affected
Red Hat JBoss Enterprise Application Platform 6
jbossweb
Not affected
Red Hat JBoss Enterprise Application Platform 7
undertow-core
Affected
Red Hat JBoss Enterprise Web Server 3
httpd
Out of support scope
Red Hat JBoss Fuse 6
undertow
Out of support scope
Red Hat JBoss Web Server 5
nghttp2
Not affected
Red Hat OpenShift Application Runtimes
rhoar-nodejs
Out of support scope
Red Hat OpenShift Application Runtimes
undertow
Not affected
Red Hat OpenShift Container Platform 3.10
atomic-openshift
Not affected
Red Hat OpenShift Container Platform 3.10
nodejs
Not affected
Red Hat OpenShift Container Platform 3.11
atomic-openshift
Not affected
Red Hat OpenShift Container Platform 3.9
atomic-openshift
Not affected
Red Hat OpenShift Container Platform 3.9
nodejs
Not affected
Red Hat OpenShift Container Platform 4
openshift
Not affected
Red Hat Process Automation 7
undertow
Not affected
Red Hat Quay 3
nodejs
Not affected
Red Hat Single Sign-On 7
undertow
Not affected
Red Hat Software Collections
rh-nginx110-nginx
Not affected
Red Hat Software Collections
rh-nginx112-nginx
Not affected
Red Hat Software Collections
rh-nginx114-nginx
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| JBoss Core Services on RHEL 6 | jbcs-httpd24-apr-0:1.6.3-63.jbcs.el6 | Fixed | RHSA-2019:3932 |
| JBoss Core Services on RHEL 6 | jbcs-httpd24-apr-util-0:1.6.1-48.jbcs.el6 | Fixed | RHSA-2019:3932 |
| JBoss Core Services on RHEL 6 | jbcs-httpd24-brotli-0:1.0.6-7.jbcs.el6 | Fixed | RHSA-2019:3932 |
| JBoss Core Services on RHEL 6 | jbcs-httpd24-curl-0:7.64.1-14.jbcs.el6 | Fixed | RHSA-2019:3932 |
| JBoss Core Services on RHEL 6 | jbcs-httpd24-httpd-0:2.4.29-41.jbcs.el6 | Fixed | RHSA-2019:2946 |
| JBoss Core Services on RHEL 6 | jbcs-httpd24-httpd-0:2.4.37-33.jbcs.el6 | Fixed | RHSA-2019:3932 |
| JBoss Core Services on RHEL 6 | jbcs-httpd24-jansson-0:2.11-20.jbcs.el6 | Fixed | RHSA-2019:3932 |
| JBoss Core Services on RHEL 6 | jbcs-httpd24-mod_cluster-native-0:1.3.12-9.Final_redhat_2.jbcs.el6 | Fixed | RHSA-2019:3932 |
| JBoss Core Services on RHEL 6 | jbcs-httpd24-mod_jk-0:1.2.46-22.redhat_1.jbcs.el6 | Fixed | RHSA-2019:3932 |
| JBoss Core Services on RHEL 6 | jbcs-httpd24-mod_security-0:2.9.2-16.GA.jbcs.el6 | Fixed | RHSA-2019:3932 |
| JBoss Core Services on RHEL 6 | jbcs-httpd24-nghttp2-0:1.39.2-1.jbcs.el6 | Fixed | RHSA-2019:2946 |
| JBoss Core Services on RHEL 6 | jbcs-httpd24-nghttp2-0:1.39.2-4.jbcs.el6 | Fixed | RHSA-2019:3932 |
| JBoss Core Services on RHEL 6 | jbcs-httpd24-openssl-1:1.1.1-25.jbcs.el6 | Fixed | RHSA-2019:3932 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-apr-0:1.6.3-63.jbcs.el7 | Fixed | RHSA-2019:3933 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-apr-util-0:1.6.1-48.jbcs.el7 | Fixed | RHSA-2019:3933 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-brotli-0:1.0.6-7.jbcs.el7 | Fixed | RHSA-2019:3933 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-curl-0:7.64.1-14.jbcs.el7 | Fixed | RHSA-2019:3933 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-httpd-0:2.4.29-41.jbcs.el7 | Fixed | RHSA-2019:2946 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-httpd-0:2.4.37-33.jbcs.el7 | Fixed | RHSA-2019:3933 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-jansson-0:2.11-20.jbcs.el7 | Fixed | RHSA-2019:3933 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-mod_cluster-native-0:1.3.12-9.Final_redhat_2.jbcs.el7 | Fixed | RHSA-2019:3933 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-mod_jk-0:1.2.46-22.redhat_1.jbcs.el7 | Fixed | RHSA-2019:3933 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-mod_security-0:2.9.2-16.GA.jbcs.el7 | Fixed | RHSA-2019:3933 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-nghttp2-0:1.39.2-1.jbcs.el7 | Fixed | RHSA-2019:2946 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-nghttp2-0:1.39.2-4.jbcs.el7 | Fixed | RHSA-2019:3933 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-openssl-1:1.1.1-25.jbcs.el7 | Fixed | RHSA-2019:3933 |
| Red Hat AMQ | n/a | Fixed | RHSA-2020:0922 |
| Red Hat AMQ 7.4.3 | n/a | Fixed | RHSA-2020:1445 |
| Red Hat Enterprise Linux 8 | httpd:2.4-8000020190829150747.f8e95b4e | Fixed | RHSA-2019:2893 |
| Red Hat Enterprise Linux 8 | nodejs:10-8000020190911085529.f8e95b4e | Fixed | RHSA-2019:2925 |
| Red Hat Fuse 7.6.0 | undertow | Fixed | RHSA-2020:0983 |
| Red Hat JBoss Core Services | n/a | Fixed | RHSA-2019:3935 |
| Red Hat JBoss Core Services | mod_http2 | Fixed | RHSA-2019:2950 |
| Red Hat Software Collections for Red Hat Enterprise Linux 6 | httpd24-httpd-0:2.4.34-8.el6.1 | Fixed | RHSA-2019:2949 |
| Red Hat Software Collections for Red Hat Enterprise Linux 6 | httpd24-nghttp2-0:1.7.1-7.el6.1 | Fixed | RHSA-2019:2949 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | httpd24-httpd-0:2.4.34-8.el7.1 | Fixed | RHSA-2019:2949 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | httpd24-nghttp2-0:1.7.1-7.el7.1 | Fixed | RHSA-2019:2949 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-nodejs10-0:3.2-3.el7 | Fixed | RHSA-2019:2939 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-nodejs10-nodejs-0:10.16.3-3.el7 | Fixed | RHSA-2019:2939 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-nodejs8-0:3.0-5.el7 | Fixed | RHSA-2019:2955 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-nodejs8-nodejs-0:8.16.1-2.el7 | Fixed | RHSA-2019:2955 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS | httpd24-httpd-0:2.4.34-8.el7.1 | Fixed | RHSA-2019:2949 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS | httpd24-nghttp2-0:1.7.1-7.el7.1 | Fixed | RHSA-2019:2949 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS | rh-nodejs10-0:3.2-3.el7 | Fixed | RHSA-2019:2939 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS | rh-nodejs10-nodejs-0:10.16.3-3.el7 | Fixed | RHSA-2019:2939 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS | rh-nodejs8-0:3.0-5.el7 | Fixed | RHSA-2019:2955 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS | rh-nodejs8-nodejs-0:8.16.1-2.el7 | Fixed | RHSA-2019:2955 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | httpd24-httpd-0:2.4.34-8.el7.1 | Fixed | RHSA-2019:2949 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | httpd24-nghttp2-0:1.7.1-7.el7.1 | Fixed | RHSA-2019:2949 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | rh-nodejs10-0:3.2-3.el7 | Fixed | RHSA-2019:2939 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | rh-nodejs10-nodejs-0:10.16.3-3.el7 | Fixed | RHSA-2019:2939 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | rh-nodejs8-0:3.0-5.el7 | Fixed | RHSA-2019:2955 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | rh-nodejs8-nodejs-0:8.16.1-2.el7 | Fixed | RHSA-2019:2955 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | httpd24-httpd-0:2.4.34-8.el7.1 | Fixed | RHSA-2019:2949 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | httpd24-nghttp2-0:1.7.1-7.el7.1 | Fixed | RHSA-2019:2949 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | rh-nodejs10-0:3.2-3.el7 | Fixed | RHSA-2019:2939 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | rh-nodejs10-nodejs-0:10.16.3-3.el7 | Fixed | RHSA-2019:2939 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | rh-nodejs8-0:3.0-5.el7 | Fixed | RHSA-2019:2955 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | rh-nodejs8-nodejs-0:8.16.1-2.el7 | Fixed | RHSA-2019:2955 |
| CloudForms Management Engine 5 | nginx | Not affected | n/a |
| Red Hat AMQ Broker 7 | jetty | Affected | n/a |
| Red Hat Ansible Tower 3 | nginx | Not affected | n/a |
| Red Hat Enterprise Linux 8 | nghttp2 | Not affected | n/a |
| Red Hat Enterprise Linux 8 | nginx:1.14/nginx | Not affected | n/a |
| Red Hat JBoss Data Grid 7 | undertow | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | jbossweb | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | undertow-core | Affected | n/a |
| Red Hat JBoss Enterprise Web Server 3 | httpd | Out of support scope | n/a |
| Red Hat JBoss Fuse 6 | undertow | Out of support scope | n/a |
| Red Hat JBoss Web Server 5 | nghttp2 | Not affected | n/a |
| Red Hat OpenShift Application Runtimes | rhoar-nodejs | Out of support scope | n/a |
| Red Hat OpenShift Application Runtimes | undertow | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.10 | atomic-openshift | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.10 | nodejs | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.11 | atomic-openshift | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.9 | atomic-openshift | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.9 | nodejs | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift | Not affected | n/a |
| Red Hat Process Automation 7 | undertow | Not affected | n/a |
| Red Hat Quay 3 | nodejs | Not affected | n/a |
| Red Hat Single Sign-On 7 | undertow | Not affected | n/a |
| Red Hat Software Collections | rh-nginx110-nginx | Not affected | n/a |
| Red Hat Software Collections | rh-nginx112-nginx | Not affected | n/a |
| Red Hat Software Collections | rh-nginx114-nginx | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
The package httpd versions as shipped with Red Hat Enterprise Linux 5, 6 and 7 are not affected by this issue as HTTP/2 support is not provided. This flaw has no available mitigation for nodejs package. It will be updated once the available fixes are released for Red Hat Enterprise Linux and Red Hat Software Collections. The nodejs RPM shipped in OpenShift Container Platform 3.9 and 3.10 is not affected by this flaw as it does not contain the vulnerable code.
Red Hat mitigation
The httpd version shipped with Red Hat Enterprise Linux 8 provides HTTP/2 support through mod_http2 package. While mod_http2 package is not updated, users can disable HTTP/2 support as mitigation action by executing the following steps: 1. Stop httpd service: $ systemctl stop httpd 2. Remove http/2 protocol support from configuration files: $ sed -i 's/\(h2\)\|\(h2c\)//g' <httpd_config_file> 3. Validate configuration files to make sure all syntax is valid: $ apachectl configtest 4. Restart httpd service: $ systemctl start httpd
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
AV:N/AC:L/Au:N/C:N/I:N/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (49 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 27.89% (0.27890) | 98.05th | v5 (v2026.06.15) |
| Jun 15, 2026 | 27.21% (0.27214) | 97.79th | v5 (v2026.06.15) |
| Apr 29, 2026 | 4.65% (0.04647) | 89.33th | v4 (v2025.03.14) |
| Apr 4, 2026 | 5.96% (0.05964) | 90.62th | v4 (v2025.03.14) |
| Mar 4, 2026 | 4.56% (0.04564) | 88.98th | v4 (v2025.03.14) |
| Mar 1, 2026 | 1.61% (0.01609) | 81.55th | v4 (v2025.03.14) |
| Feb 4, 2026 | 4.68% (0.04684) | 89.07th | v4 (v2025.03.14) |
| Feb 1, 2026 | 1.65% (0.01653) | 81.72th | v4 (v2025.03.14) |
| Jan 4, 2026 | 4.56% (0.04564) | 88.84th | v4 (v2025.03.14) |
| Jan 1, 2026 | 1.61% (0.01609) | 81.41th | v4 (v2025.03.14) |
| Dec 4, 2025 | 4.56% (0.04564) | 88.77th | v4 (v2025.03.14) |
| Dec 1, 2025 | 1.61% (0.01609) | 81.28th | v4 (v2025.03.14) |
| Nov 21, 2025 | 4.56% (0.04564) | 88.71th | v4 (v2025.03.14) |
| Nov 18, 2025 | 69.89% (0.69895) | 98.71th | v4 (v2025.03.14) |
| Nov 4, 2025 | 4.56% (0.04564) | 88.68th | v4 (v2025.03.14) |
| Nov 1, 2025 | 1.61% (0.01609) | 81.22th | v4 (v2025.03.14) |
| Oct 4, 2025 | 4.56% (0.04564) | 88.72th | v4 (v2025.03.14) |
| Oct 1, 2025 | 1.61% (0.01609) | 81.17th | v4 (v2025.03.14) |
| Sep 4, 2025 | 4.50% (0.04499) | 88.70th | v4 (v2025.03.14) |
| Sep 1, 2025 | 1.58% (0.01585) | 80.98th | v4 (v2025.03.14) |
| Aug 4, 2025 | 4.50% (0.04499) | 88.69th | v4 (v2025.03.14) |
| Aug 1, 2025 | 1.58% (0.01585) | 80.94th | v4 (v2025.03.14) |
| Jul 4, 2025 | 4.56% (0.04564) | 88.72th | v4 (v2025.03.14) |
| Jul 1, 2025 | 1.61% (0.01609) | 80.96th | v4 (v2025.03.14) |
| Jun 4, 2025 | 4.56% (0.04564) | 88.65th | v4 (v2025.03.14) |
| Jun 1, 2025 | 1.61% (0.01609) | 80.92th | v4 (v2025.03.14) |
| May 4, 2025 | 4.56% (0.04564) | 88.56th | v4 (v2025.03.14) |
| May 1, 2025 | 1.61% (0.01609) | 80.81th | v4 (v2025.03.14) |
| Mar 30, 2025 | 4.56% (0.04564) | 88.17th | v4 (v2025.03.14) |
| Mar 29, 2025 | 8.83% (0.08827) | 87.35th | v4 (v2025.03.14) |
| Mar 17, 2025 | 4.56% (0.04564) | 88.46th | v4 (v2025.03.14) |
| Jan 3, 2025 | 8.25% (0.08252) | 94.36th | v3 (v2023.03.01) |
| Dec 17, 2024 | 9.57% (0.09575) | 94.76th | v3 (v2023.03.01) |
| Dec 12, 2024 | 3.53% (0.03532) | 91.93th | v3 (v2023.03.01) |
| Mar 8, 2024 | 3.56% (0.03558) | 91.33th | v3 (v2023.03.01) |
| Feb 9, 2024 | 3.78% (0.03780) | 91.53th | v3 (v2023.03.01) |
| Nov 22, 2023 | 3.50% (0.03496) | 90.51th | v3 (v2023.03.01) |
| Nov 8, 2023 | 3.87% (0.03866) | 90.92th | v3 (v2023.03.01) |
| Jul 4, 2023 | 0.40% (0.00396) | 69.80th | v3 (v2023.03.01) |
| Jun 17, 2023 | 0.34% (0.00345) | 67.54th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.34% (0.00337) | 66.69th | v3 (v2023.03.01) |
| Mar 6, 2023 | 7.77% (0.07767) | 93.09th | v2 (v2022.01.01) |
| Apr 1, 2022 | 7.77% (0.07767) | 92.44th | v2 (v2022.01.01) |
| Feb 4, 2022 | 44.26% (0.44262) | 97.72th | v2 (v2022.01.01) |
| Feb 3, 2022 | 20.15% (0.20150) | 94.14th | v1 |
| Jan 6, 2022 | 20.15% (0.20150) | 94.07th | v1 |
| Sep 1, 2021 | 5.33% (0.05325) | 88.22th | v1 |
| Jun 8, 2021 | 5.33% (0.05325) | 0.00th | v1 |
| Apr 14, 2021 | 5.22% (0.05219) | 0.00th | v1 |
References (52)
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00004.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00031.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00032.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2019/08/15/7 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2893 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2925 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2939 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2946 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2949 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2950 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2955 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3932 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3933 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3935 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-9517 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1741868 Issue Tracking
- https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-002.md x_refsource_MISCThird Party Advisory
- https://kb.cert.org/vuls/id/605641/ third-party-advisoryx_refsource_CERT-VNThird Party AdvisoryUS Government Resource
- https://kc.mcafee.com/corporate/index?page=content&id=SB10296 x_refsource_CONFIRMThird Party Advisory
- https://lists.apache.org/thread.html/4610762456644181b267c846423b3a990bd4aaea1886ecc7d51febdb%40%3Cannounce.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/d89f999e26dfb1d50f247ead1fe8538014eb412b2dbe5be4b1a9ef50%40%3Cdev.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/ec97fdfc1a859266e56fef084353a34e0a0b08901b3c1aa317a43c8c%40%3Cdev.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r03ee478b3dda3e381fd6189366fa7af97c980d2f602846eef935277d%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r06f0d87ebb6d59ed8379633f36f72f5b1f79cadfda72ede0830b42cf%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r3c5c3104813c1c5508b55564b66546933079250a46ce50eee90b2e36%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r76142b8c5119df2178be7c2dba88fde552eedeec37ea993dfce68d1d%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rc998b18880df98bafaade071346690c2bc1444adaa1a1ea464b93f0a%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0456cc582390b6f%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rd2fb621142e7fa187cfe12d7137bf66e7234abcbbcd800074c84a538%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/re3d27b6250aa8548b8845d314bb8a350b3df326cacbbfdfe4d455234%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4ZQGHE3WTYLYAYJEIDJVF2FIGQTAYPMC/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BP556LEG3WENHZI5TAQ6ZEBFTJB4E2IS/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CMNFX5MNYRWWIMO4BTKYQCGUDMHO3AXP/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XHTKU7YQ5EEP2XNSAV4M4VJ7QCBOJMOD/ vendor-advisoryx_refsource_FEDORA
- https://nodejs.org/en/blog/vulnerability/aug-2019-security-releases/
- https://nvd.nist.gov/vuln/detail/CVE-2019-9517
- https://seclists.org/bugtraq/2019/Aug/47 mailing-listx_refsource_BUGTRAQMailing ListThird Party Advisory
- https://security.gentoo.org/glsa/201909-04 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://security.netapp.com/advisory/ntap-20190823-0003/ x_refsource_CONFIRMThird Party Advisory
- https://security.netapp.com/advisory/ntap-20190823-0005/ x_refsource_CONFIRMThird Party Advisory
- https://security.netapp.com/advisory/ntap-20190905-0003/ x_refsource_CONFIRMThird Party Advisory
- https://support.f5.com/csp/article/K02591030 x_refsource_CONFIRMThird Party Advisory
- https://support.f5.com/csp/article/K02591030?utm_source=f5support&%3Butm_medium=RSS x_refsource_CONFIRM
- https://usn.ubuntu.com/4113-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-9517
- https://www.debian.org/security/2019/dsa-4509 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2020.html x_refsource_MISCThird Party Advisory
- https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html x_refsource_MISCPatchThird Party Advisory
- https://www.synology.com/security/advisory/Synology_SA_19_33 x_refsource_CONFIRMThird Party Advisory
Change history (0)
No recorded changes yet.