CVE-2019-9512: Apache Traffic Server

High severity, CVSS 7.5. EPSS: 83.4% chance of exploitation in the next 30 days.

Some HTTP/2 implementations are vulnerable to ping floods, potentially leading to a denial of service. The attacker sends continual pings to an HTTP/2 peer, causing the peer to build an internal queue of responses. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both.

Affected products

  • Apache Traffic Server: from 6.0.0, up to and including 6.2.3; from 7.0.0, up to and including 7.1.6; from 8.0.0, up to and including 8.0.3
  • Apple Swiftnio: from 1.0.0, up to and including 1.4.0
  • Debian Debian Linux: version 10.0 only
  • Node.js Node.js: from 8.0.0, up to and including 8.8.1; from 8.9.0, before 8.16.1 (fixed in 8.16.1); from 10.0.0, up to and including 10.12.0; from 10.13.0, before 10.16.3 (fixed in 10.16.3); from 12.0.0, before 12.8.1 (fixed in 12.8.1)

Published 2019-08-13. Last modified 2026-06-17.