CVE-2019-9512
HIGH7.5EPSS 50.8%golang.org/x/net/http vulnerable to a reset flood
Published: 5/24/2022Modified: 4/28/2026
Description
Some HTTP/2 implementations are vulnerable to ping floods, potentially leading to a denial of service. The attacker sends continual pings to an HTTP/2 peer, causing the peer to build an internal queue of responses. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both.
Affected packages (9)
- Alpine/nodejsfrom 0, < 10.16.3-r0
- Debian/golang-golang-x-net-devfrom 0, < 1:0.0+git20161013.8b4af36+dfsg-3+deb9u1
- Debian/h2ofrom 0, < 2.2.5+dfsg2-3
- Debian/h2ofrom 0, < 2.2.5+dfsg2-2+deb10u1
- Debian/trafficserverfrom 0, < 8.0.5+ds-1
- Go/golang.org/x/netfrom 0, < 0.0.0-20190813141303-74dc4d7220e7
- Go/golang.org/x/netfrom 0, < 0.0.0-20190813141303-74dc4d7220e7
- Go/golang.org/x/netfrom 0, < 0.0.0-20190813141303-74dc4d7220e7
- Go/stdlibfrom 0, < 1.11.13, >= 1.12.0-0, < 1.12.8
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
References (78)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2019-9512
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2019-9514
- ADVISORYhttps://security.alpinelinux.org/vuln/CVE-2019-9512
- ADVISORYhttps://security-tracker.debian.org/tracker/CVE-2019-9512
- WEBhttp://lists.opensuse.org/opensuse-security-announce/2019-08/msg00076.html
- WEBhttp://lists.opensuse.org/opensuse-security-announce/2019-09/msg00002.html
- WEBhttp://lists.opensuse.org/opensuse-security-announce/2019-09/msg00011.html
- WEBhttp://lists.opensuse.org/opensuse-security-announce/2019-09/msg00021.html
- WEBhttp://lists.opensuse.org/opensuse-security-announce/2019-09/msg00031.html
- WEBhttp://lists.opensuse.org/opensuse-security-announce/2019-09/msg00032.html
- WEBhttp://lists.opensuse.org/opensuse-security-announce/2019-09/msg00038.html
- WEBhttps://access.redhat.com/errata/RHSA-2019:2594
- WEBhttps://access.redhat.com/errata/RHSA-2019:2661
- WEBhttps://access.redhat.com/errata/RHSA-2019:2682
- WEBhttps://access.redhat.com/errata/RHSA-2019:2690
- WEBhttps://access.redhat.com/errata/RHSA-2019:2726
- WEBhttps://access.redhat.com/errata/RHSA-2019:2766
- WEBhttps://access.redhat.com/errata/RHSA-2019:2769
- WEBhttps://access.redhat.com/errata/RHSA-2019:2796
- WEBhttps://access.redhat.com/errata/RHSA-2019:2861
- WEBhttps://access.redhat.com/errata/RHSA-2019:2925
- WEBhttps://access.redhat.com/errata/RHSA-2019:2939
- WEBhttps://access.redhat.com/errata/RHSA-2019:2955
- WEBhttps://access.redhat.com/errata/RHSA-2019:2966
- WEBhttps://access.redhat.com/errata/RHSA-2019:3131
- WEBhttps://access.redhat.com/errata/RHSA-2019:3245
- WEBhttps://access.redhat.com/errata/RHSA-2019:3265
- WEBhttps://access.redhat.com/errata/RHSA-2019:3892
- WEBhttps://access.redhat.com/errata/RHSA-2019:3906
- WEBhttps://access.redhat.com/errata/RHSA-2019:4018
- WEBhttps://access.redhat.com/errata/RHSA-2019:4019
- WEBhttps://access.redhat.com/errata/RHSA-2019:4020
- WEBhttps://access.redhat.com/errata/RHSA-2019:4021
- WEBhttps://access.redhat.com/errata/RHSA-2019:4040
- WEBhttps://access.redhat.com/errata/RHSA-2019:4041
- WEBhttps://access.redhat.com/errata/RHSA-2019:4042
- WEBhttps://access.redhat.com/errata/RHSA-2019:4045
- WEBhttps://access.redhat.com/errata/RHSA-2019:4269
- WEBhttps://access.redhat.com/errata/RHSA-2019:4273
- WEBhttps://access.redhat.com/errata/RHSA-2019:4352
- WEBhttps://access.redhat.com/errata/RHSA-2020:0406
- WEBhttps://access.redhat.com/errata/RHSA-2020:0727
- WEBhttp://seclists.org/fulldisclosure/2019/Aug/16
- WEBhttps://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-002.md
- WEBhttps://go.dev/cl/190137
- WEBhttps://go.dev/issue/33606
- WEBhttps://go.googlesource.com/go/+/145e193131eb486077b66009beb051aba07c52a5
- WEBhttps://groups.google.com/g/golang-announce/c/65QixT3tcmg/m/DrFiG6vvCwAJ
- WEBhttps://kb.cert.org/vuls/id/605641
- WEBhttps://kc.mcafee.com/corporate/index?page=content&id=SB10296
- … 28 more