CVE-2019-9515: Apache Traffic Server
High severity, CVSS 7.5. EPSS: 87.4% chance of exploitation in the next 30 days.
Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service. The attacker sends a stream of SETTINGS frames to the peer. Since the RFC requires that the peer reply with one acknowledgement per SETTINGS frame, an empty SETTINGS frame is almost equivalent in behavior to a ping. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both.
Affected products
- Apache Traffic Server: from 6.0.0, up to and including 6.2.3; from 7.0.0, up to and including 7.1.6; from 8.0.0, up to and including 8.0.3
- Apple Swiftnio: from 1.0.0, up to and including 1.4.0
- Canonical Ubuntu Linux: version 16.04 only; version 18.04 only; version 19.04 only
- Debian Debian Linux: version 9.0 only; version 10.0 only
- F5 BIG-IP Local Traffic Manager: from 11.6.1, before 11.6.5.1 (fixed in 11.6.5.1); from 12.1.0, before 12.1.5.1 (fixed in 12.1.5.1); from 13.1.0, before 13.1.3.2 (fixed in 13.1.3.2); from 14.0.0, before 14.0.1.1 (fixed in 14.0.1.1); from 14.1.0, before 14.1.2.1 (fixed in 14.1.2.1); from 15.0.0, before 15.0.1.1 (fixed in 15.0.1.1)
- Fedoraproject Fedora: version 29 only; version 30 only
- McAfee Web Gateway: from 7.7.2.0, before 7.7.2.24 (fixed in 7.7.2.24); from 7.8.2.0, before 7.8.2.13 (fixed in 7.8.2.13); from 8.1.0, before 8.2.0 (fixed in 8.2.0)
- Node.js Node.js: from 8.0.0, up to and including 8.8.1; from 8.9.0, before 8.16.1 (fixed in 8.16.1); from 10.0.0, up to and including 10.12.0; from 10.13.0, before 10.16.3 (fixed in 10.16.3); from 12.0.0, before 12.8.1 (fixed in 12.8.1)
- Opensuse Leap: version 15.0 only; version 15.1 only
- Oracle Graalvm: version 19.2.0 only
- Red Hat Enterprise Linux: version 8.0 only
- Red Hat JBoss Core Services: version 1.0 only
- Red Hat JBoss Enterprise Application Platform: version 7.2.0 only; version 7.3.0 only
- Red Hat Openshift Container Platform: version 4.1 only
- Red Hat Openshift Service Mesh: version 1.0 only
- Red Hat Openstack: version 14 only
- Red Hat Quay: version 3.0.0 only
- Red Hat Single Sign-On: version 7.3 only
- Red Hat Software Collections: version 1.0 only
- Synology Diskstation Manager: version 6.2 only
- Synology Skynas: affected versions not specified
- Synology VS960HD Firmware: affected versions not specified
Published 2019-08-13. Last modified 2026-06-17.