CVE-2019-9516: Apache Traffic Server
Medium severity, CVSS 6.5. EPSS: 56.3% chance of exploitation in the next 30 days.
Some HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of service. The attacker sends a stream of headers with a 0-length header name and 0-length header value, optionally Huffman encoded into 1-byte or greater headers. Some implementations allocate memory for these headers and keep the allocation alive until the session dies. This can consume excess memory.
Affected products
- Apache Traffic Server: from 6.0.0, up to and including 6.2.3; from 7.0.0, up to and including 7.1.6; from 8.0.0, up to and including 8.0.3
- Apple Swiftnio: from 1.0.0, up to and including 1.4.0
- Canonical Ubuntu Linux: version 16.04 only; version 18.04 only; version 19.04 only
- Debian Debian Linux: version 9.0 only; version 10.0 only
- F5 Nginx: from 1.9.5, before 1.16.1 (fixed in 1.16.1); from 1.17.0, up to and including 1.17.2
- Fedoraproject Fedora: version 30 only; version 29 only; version 32 only
- McAfee Web Gateway: from 7.7.2.0, before 7.7.2.24 (fixed in 7.7.2.24); from 7.8.2.0, before 7.8.2.13 (fixed in 7.8.2.13); from 8.1.0, before 8.2.0 (fixed in 8.2.0)
- Node.js Node.js: from 8.0.0, before 8.16.1 (fixed in 8.16.1); from 10.0.0, before 10.16.3 (fixed in 10.16.3); from 12.0.0, before 12.8.1 (fixed in 12.8.1)
- Opensuse Leap: version 15.0 only; version 15.1 only
- Oracle Graalvm: version 19.2.0 only
- Red Hat Enterprise Linux: version 8.0 only
- Red Hat JBoss Core Services: version 1.0 only
- Red Hat JBoss Enterprise Application Platform: version 7.2.0 only; version 7.3.0 only
- Red Hat Openshift Service Mesh: version 1.0 only
- Red Hat Quay: version 3.0.0 only
- Red Hat Software Collections: version 1.0 only
- Synology Diskstation Manager: version 6.2 only
- Synology Skynas: affected versions not specified
- Synology VS960HD Firmware: affected versions not specified
Published 2019-08-13. Last modified 2026-06-17.