FlawAtlas
Search the atlas
UBUNTU-CVE-2019-9511 High

UBUNTU-CVE-2019-9511

Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service. The attacker requests a large amount of data from a specified resource over multiple streams. They manipulate window size and stream priority to force the server to queue the data in 1-byte chunks. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both.

Exploit probability Not scored
Published August 13, 2019
Required by Not available
Last source change April 22, 2026

02 / AFFECTED SOFTWARE

Affected packages

Ubuntu:16.04:LTS nginx

20 explicit affected versions

Ubuntu:18.04:LTS nginx

9 explicit affected versions

Ubuntu:Pro:14.04:LTS nodejs

12 explicit affected versions

Ubuntu:Pro:16.04:LTS nghttp2

9 explicit affected versions

Ubuntu:Pro:16.04:LTS nodejs

12 explicit affected versions

Ubuntu:Pro:18.04:LTS nghttp2

8 explicit affected versions

Ubuntu:Pro:18.04:LTS nodejs

15 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities UBUNTU-CVE-2019-9511

Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service. The attacker requests a large amount of data from a specified resource over multiple streams. They manipulate window size and stream priority to force the server to queue the data in 1-byte chunks. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both.

View original source

05 / REFERENCES

Further evidence