ZeroHour

CVE-2019-9512

CVSS 3.1
7.5 high
EPSS
83%p100
Published
()
Modified
Description

Some HTTP/2 implementations are vulnerable to ping floods, potentially leading to a denial of service. The attacker sends continual pings to an HTTP/2 peer, causing the peer to build an internal queue of responses. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both.

Vendors
appleapachedebiannodejs
Products
swiftnio, traffic server, debian linux, node.js
Weakness
CWE-400
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news