CVE-2019-19337: Red Hat Ceph Storage

Medium severity, CVSS 6.5. EPSS: 1.3% chance of exploitation in the next 30 days.

A flaw was found in Red Hat Ceph Storage version 3 in the way the Ceph RADOS Gateway daemon handles S3 requests. An authenticated attacker can abuse this flaw by causing a remote denial of service by sending a specially crafted HTTP Content-Length header to the Ceph RADOS Gateway server.

Affected products

  • Red Hat Ceph Storage: version 3.3 only

Published 2019-12-23. Last modified 2026-06-17.