CVE-2019-9514: Apache Traffic Server

High severity, CVSS 7.5. EPSS: 82.8% chance of exploitation in the next 30 days.

Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of streams and sends an invalid request over each stream that should solicit a stream of RST_STREAM frames from the peer. Depending on how the peer queues the RST_STREAM frames, this can consume excess memory, CPU, or both.

Affected products

  • Apache Traffic Server: from 6.0.0, up to and including 6.2.3; from 7.0.0, up to and including 7.1.6; from 8.0.0, up to and including 8.0.3
  • Apple Swiftnio: from 1.0.0, up to and including 1.4.0
  • Canonical Ubuntu Linux: version 16.04 only; version 18.04 only; version 19.04 only
  • Debian Debian Linux: version 10.0 only; version 9.0 only
  • F5 BIG-IP Local Traffic Manager: from 11.6.1, before 11.6.5.1 (fixed in 11.6.5.1); from 12.1.0, before 12.1.5.1 (fixed in 12.1.5.1); from 13.1.0, before 13.1.3.2 (fixed in 13.1.3.2); from 14.0.0, before 14.0.1.1 (fixed in 14.0.1.1); from 14.1.0, before 14.1.2.1 (fixed in 14.1.2.1); from 15.0.0, before 15.0.1.1 (fixed in 15.0.1.1)
  • Fedoraproject Fedora: version 29 only; version 30 only
  • McAfee Web Gateway: from 7.7.2.0, before 7.7.2.24 (fixed in 7.7.2.24); from 7.8.2.0, before 7.8.2.13 (fixed in 7.8.2.13); from 8.1.0, before 8.2.0 (fixed in 8.2.0)
  • Netapp Cloud Insights: affected versions not specified
  • Netapp Trident: affected versions not specified
  • Node.js Node.js: from 8.0.0, up to and including 8.8.1; from 8.9.0, before 8.16.1 (fixed in 8.16.1); from 10.0.0, up to and including 10.12.0; from 10.13.0, before 10.16.3 (fixed in 10.16.3); from 12.0.0, before 12.8.1 (fixed in 12.8.1)
  • Opensuse Leap: version 15.0 only; version 15.1 only
  • Oracle Graalvm: version 19.2.0 only
  • Red Hat Developer Tools: version 1.0 only
  • Red Hat Enterprise Linux: version 8.0 only
  • Red Hat Enterprise Linux Eus: version 8.1 only
  • Red Hat Enterprise Linux Server: version 7.0 only
  • Red Hat Enterprise Linux Workstation: version 7.0 only
  • Red Hat JBoss Core Services: version 1.0 only
  • Red Hat JBoss Enterprise Application Platform: version 7.2.0 only; version 7.3.0 only
  • Red Hat Openshift Container Platform: version 3.9 only; version 3.10 only; version 3.11 only; version 4.1 only; version 4.2 only
  • Red Hat Openshift Service Mesh: version 1.0 only
  • Red Hat Openstack: version 14 only
  • Red Hat Quay: version 3.0.0 only
  • Red Hat Single Sign-On: version 7.3 only
  • Red Hat Software Collections: version 1.0 only
  • and 3 more

Published 2019-08-13. Last modified 2026-06-17.