CVE-2019-9517: Apache HTTP Server

High severity, CVSS 7.5. EPSS: 27.9% chance of exploitation in the next 30 days.

Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to a denial of service. The attacker opens the HTTP/2 window so the peer can send without constraint; however, they leave the TCP window closed so the peer cannot actually write (many of) the bytes on the wire. The attacker then sends a stream of requests for a large response object. Depending on how the servers queue the responses, this can consume excess memory, CPU, or both.

Affected products

  • Apache HTTP Server: from 2.4.20, before 2.4.40 (fixed in 2.4.40)
  • Apache Traffic Server: from 6.0.0, up to and including 6.2.3; from 7.0.0, up to and including 7.1.6; from 8.0.0, up to and including 8.0.3
  • Apple Swiftnio: from 1.0.0, up to and including 1.4.0
  • Canonical Ubuntu Linux: version 16.04 only; version 18.04 only; version 19.04 only
  • Debian Debian Linux: version 9.0 only; version 10.0 only
  • Fedoraproject Fedora: version 29 only; version 30 only
  • McAfee Web Gateway: from 7.7.2.0, before 7.7.2.24 (fixed in 7.7.2.24); from 7.8.2.0, before 7.8.2.13 (fixed in 7.8.2.13); from 8.1.0, before 8.2.0 (fixed in 8.2.0)
  • Netapp Clustered Data Ontap: affected versions not specified
  • Node.js Node.js: from 8.0.0, up to and including 8.8.1; from 8.9.0, before 8.16.1 (fixed in 8.16.1); from 10.0.0, up to and including 10.12.0; from 10.13.0, before 10.16.3 (fixed in 10.16.3); from 12.0.0, before 12.8.1 (fixed in 12.8.1)
  • Opensuse Leap: version 15.0 only; version 15.1 only
  • Oracle Communications Element Manager: version 8.0.0 only; version 8.1.0 only; version 8.1.1 only; version 8.2.0 only
  • Oracle Graalvm: version 19.2.0 only
  • Oracle Instantis Enterprisetrack: from 17.1, up to and including 17.3
  • Oracle Retail Xstore Point Of Service: version 7.1 only
  • Red Hat Enterprise Linux: version 8.0 only
  • Red Hat JBoss Core Services: version 1.0 only
  • Red Hat JBoss Enterprise Application Platform: version 7.2.0 only; version 7.3.0 only
  • Red Hat Openshift Service Mesh: version 1.0 only
  • Red Hat Quay: version 3.0.0 only
  • Red Hat Software Collections: version 1.0 only
  • Synology Diskstation Manager: version 6.2 only
  • Synology Skynas: affected versions not specified
  • Synology VS960HD Firmware: affected versions not specified

Published 2019-08-13. Last modified 2026-06-17.