CVE-2019-9513: Apache Traffic Server

High severity, CVSS 7.5. EPSS: 81.6% chance of exploitation in the next 30 days.

Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service. The attacker creates multiple request streams and continually shuffles the priority of the streams in a way that causes substantial churn to the priority tree. This can consume excess CPU.

Affected products

  • Apache Traffic Server: from 6.0.0, up to and including 6.2.3; from 7.0.0, up to and including 7.1.6; from 8.0.0, up to and including 8.0.3
  • Apple Swiftnio: from 1.0.0, up to and including 1.4.0
  • Canonical Ubuntu Linux: version 16.04 only; version 18.04 only; version 19.04 only
  • Debian Debian Linux: version 9.0 only; version 10.0 only
  • F5 Nginx: from 1.9.5, before 1.16.1 (fixed in 1.16.1); from 1.17.0, up to and including 1.17.2
  • Fedoraproject Fedora: version 30 only; version 29 only
  • McAfee Web Gateway: from 7.7.2.0, before 7.7.2.24 (fixed in 7.7.2.24); from 7.8.2.0, before 7.8.2.13 (fixed in 7.8.2.13); from 8.1.0, before 8.2.0 (fixed in 8.2.0)
  • Node.js Node.js: from 8.0.0, up to and including 8.8.1; from 8.9.0, before 8.16.1 (fixed in 8.16.1); from 10.0.0, up to and including 10.12.0; from 10.13.0, before 10.16.3 (fixed in 10.16.3); from 12.0.0, before 12.8.1 (fixed in 12.8.1)
  • Opensuse Leap: version 15.0 only; version 15.1 only
  • Oracle Enterprise Communications Broker: version 3.1.0 only; version 3.2.0 only
  • Oracle Graalvm: version 19.2.0 only
  • Red Hat Enterprise Linux: version 8.0 only
  • Red Hat JBoss Core Services: version 1.0 only
  • Red Hat JBoss Enterprise Application Platform: version 7.2.0 only; version 7.3.0 only
  • Red Hat Openshift Service Mesh: version 1.0 only
  • Red Hat Quay: version 3.0.0 only
  • Red Hat Software Collections: version 1.0 only
  • Synology Diskstation Manager: version 6.2 only
  • Synology Skynas: affected versions not specified
  • Synology VS960HD Firmware: affected versions not specified

Published 2019-08-13. Last modified 2026-06-17.