Some HTTP/2 implementations are vulnerable to a flood of empty frames, potentially leading to a denial of service. The attacker sends a stream of frames with an empty payload and without the end-of-stream flag. These frames can be DATA, HEADERS, CONTINUATION and/or PUSH_PROMISE. The peer spends time processing each frame disproportionate to attack bandwidth. This can consume excess CPU.
                
            References
                    Configurations
                    Configuration 1 (hide)
| AND | 
                                
                                
 
  | 
                        
Configuration 2 (hide)
                                
                                
  | 
                        
Configuration 3 (hide)
                                
                                
  | 
                        
Configuration 4 (hide)
                                
                                
  | 
                        
Configuration 5 (hide)
                                
                                
  | 
                        
Configuration 6 (hide)
| AND | 
                                
                                
 
  | 
                        
Configuration 7 (hide)
                                
                                
  | 
                        
Configuration 8 (hide)
                                
                                
  | 
                        
Configuration 9 (hide)
                                
                                
  | 
                        
Configuration 10 (hide)
                                
                                
  | 
                        
Configuration 11 (hide)
                                
                                
  | 
                        
Configuration 12 (hide)
                                
                                
  | 
                        
Information
                Published : 2019-08-13 14:15
Updated : 2022-08-12 11:40
NVD link : CVE-2019-9518
Mitre link : CVE-2019-9518
JSON object : View
CWE
                
                    
                        
                        CWE-770
                        
            Allocation of Resources Without Limits or Throttling
Products Affected
                oracle
- graalvm
 
redhat
- enterprise_linux
 - jboss_enterprise_application_platform
 - openshift_service_mesh
 - jboss_core_services
 - quay
 - software_collections
 
synology
- skynas
 - diskstation_manager
 - vs960hd
 - vs960hd_firmware
 
nodejs
- node.js
 
debian
- debian_linux
 
fedoraproject
- fedora
 
canonical
- ubuntu_linux
 
apple
- swiftnio
 - mac_os_x
 
opensuse
- leap
 
apache
- traffic_server
 
mcafee
- web_gateway
 


