FlawAtlas
Search the atlas
UBUNTU-CVE-2019-9516 Moderate

UBUNTU-CVE-2019-9516

Some HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of service. The attacker sends a stream of headers with a 0-length header name and 0-length header value, optionally Huffman encoded into 1-byte or greater headers. Some implementations allocate memory for these headers and keep the allocation alive until the session dies. This can consume excess memory.

Exploit probability Not scored
Published August 13, 2019
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

Ubuntu:16.04:LTS nginx

20 explicit affected versions

Ubuntu:18.04:LTS nginx

9 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities UBUNTU-CVE-2019-9516

Some HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of service. The attacker sends a stream of headers with a 0-length header name and 0-length header value, optionally Huffman encoded into 1-byte or greater headers. Some implementations allocate memory for these headers and keep the allocation alive until the session dies. This can consume excess memory.

View original source

05 / REFERENCES

Further evidence