Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2019-9516

44
FAUCET Score

CVE-2019-9516 is a denial-of-service vulnerability affecting various HTTP/2 implementations, including those from Apache, Apple, Node.js, and Oracle. Attackers can exploit this by sending a continuous stream of zero-length HTTP/2 headers, causing vulnerable systems to excessively allocate and retain memory, leading to resource exhaustion. Rated Medium with a CVSS score of 6.5, this network-based attack requires low privileges and no user interaction, potentially resulting in high availability impact. While there is no evidence of active exploitation, public exploit code, or KEV listing, the vulnerability has garnered significant community discussion and media coverage, indicating awareness within the cybersecurity landscape.

Impacted Technologies

VendorProductVersion(s)CPE
>= 1.0.0, <= 1.4.0CPE matchmatch criteria
cpe:2.3:a:apple:swiftnio:*:*:*:*:*:*:*:*
>= 6.0.0, <= 6.2.3CPE matchmatch criteria
cpe:2.3:a:apache:traffic_server:*:*:*:*:*:*:*:*
>= 7.0.0, <= 7.1.6CPE matchmatch criteria
cpe:2.3:a:apache:traffic_server:*:*:*:*:*:*:*:*
>= 8.0.0, <= 8.0.3CPE matchmatch criteria
cpe:2.3:a:apache:traffic_server:*:*:*:*:*:*:*:*
16.04CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*

CVSS Data

CVSS version used by this source: 3.0

7.5HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.0

Exploit Intelligence

EPSS Score
56.26%
Probability of exploitation in next 30 days
EPSS Percentile
99.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.5626 is in the 100th percentile among its peer group of 21,951 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (80)

microsoftpatch availablevia msrc
Product: cm1 nginx 1.20.1-1 on CBL Mariner 1.0Fixed in: 1.20.1-1
microsoftpatch availablevia msrc
Product: CBL Mariner 1.0 ARMFixed in: 1.20.1-1
microsoftpatch availablevia msrc
Product: CBL Mariner 1.0 x64Fixed in: 1.20.1-1
microsoftpatch availablevia msrc
Product: 17079-16820Fixed in: 1.20.1-1
netgearpatch availablevia llm_extracted
Fixed in: 1.17.3+, 1.16.1+
opensshpatch availablevia llm_extracted
Fixed in: 1.17.3
View patch
power_bipatch availablevia llm_extracted
Fixed in: 1.16.1
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 6Fixed in: jbcs-httpd24-httpd-0:2.4.37-33.jbcs.el6
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 6Fixed in: jbcs-httpd24-jansson-0:2.11-20.jbcs.el6
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 6Fixed in: jbcs-httpd24-mod_cluster-native-0:1.3.12-9.Final_redhat_2.jbcs.el6
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 6Fixed in: jbcs-httpd24-mod_jk-0:1.2.46-22.redhat_1.jbcs.el6
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 6Fixed in: jbcs-httpd24-mod_security-0:2.9.2-16.GA.jbcs.el6
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 6Fixed in: jbcs-httpd24-nghttp2-0:1.39.2-4.jbcs.el6
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 6Fixed in: jbcs-httpd24-openssl-1:1.1.1-25.jbcs.el6
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-httpd-0:2.4.29-41.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-nghttp2-0:1.39.2-1.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-apr-0:1.6.3-63.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-apr-util-0:1.6.1-48.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-brotli-0:1.0.6-7.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-curl-0:7.64.1-14.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-httpd-0:2.4.37-33.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-jansson-0:2.11-20.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-mod_cluster-native-0:1.3.12-9.Final_redhat_2.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-mod_jk-0:1.2.46-22.redhat_1.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-mod_security-0:2.9.2-16.GA.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-nghttp2-0:1.39.2-4.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-openssl-1:1.1.1-25.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat AMQ
View patch
redhatpatch availablevia redhat_api
Product: Red Hat AMQ 7.4.3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: nginx:1.14-8000020190830002848.f8e95b4e
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: nodejs:10-8000020190911085529.f8e95b4e
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Fuse 7.6.0Fixed in: undertow
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Quay 3Fixed in: quay3/clair-jwt:v2.0.9-7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 6Fixed in: rh-nginx110-nginx-1:1.10.2-9.el6.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7Fixed in: rh-nginx110-nginx-1:1.10.2-9.el7.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7Fixed in: rh-nginx112-nginx-1:1.12.1-3.el7.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7Fixed in: rh-nginx114-nginx-1:1.14.1-1.el7.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7Fixed in: rh-nodejs10-0:3.2-3.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7Fixed in: rh-nodejs10-nodejs-0:10.16.3-3.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7Fixed in: rh-nodejs8-0:3.0-5.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7Fixed in: rh-nodejs8-nodejs-0:8.16.1-2.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUSFixed in: rh-nginx110-nginx-1:1.10.2-9.el7.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUSFixed in: rh-nginx112-nginx-1:1.12.1-3.el7.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUSFixed in: rh-nginx114-nginx-1:1.14.1-1.el7.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUSFixed in: rh-nginx110-nginx-1:1.10.2-9.el7.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUSFixed in: rh-nginx112-nginx-1:1.12.1-3.el7.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUSFixed in: rh-nginx114-nginx-1:1.14.1-1.el7.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUSFixed in: rh-nodejs10-0:3.2-3.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUSFixed in: rh-nodejs10-nodejs-0:10.16.3-3.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUSFixed in: rh-nodejs8-0:3.0-5.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUSFixed in: rh-nginx110-nginx-1:1.10.2-9.el7.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUSFixed in: rh-nginx112-nginx-1:1.12.1-3.el7.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUSFixed in: rh-nginx114-nginx-1:1.14.1-1.el7.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUSFixed in: rh-nodejs10-0:3.2-3.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUSFixed in: rh-nodejs10-nodejs-0:10.16.3-3.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUSFixed in: rh-nodejs8-0:3.0-5.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUSFixed in: rh-nodejs8-nodejs-0:8.16.1-2.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUSFixed in: rh-nginx110-nginx-1:1.10.2-9.el7.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUSFixed in: rh-nginx112-nginx-1:1.12.1-3.el7.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUSFixed in: rh-nginx114-nginx-1:1.14.1-1.el7.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUSFixed in: rh-nodejs10-0:3.2-3.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUSFixed in: rh-nodejs10-nodejs-0:10.16.3-3.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUSFixed in: rh-nodejs8-0:3.0-5.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUSFixed in: rh-nodejs8-nodejs-0:8.16.1-2.el7
View patch
redhatpatch availablevia redhat_api
Product: Text-Only JBCSFixed in: mod_http2
View patch
redhatpatch availablevia redhat_api
Product: Text-Only JBCS
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUSFixed in: rh-nodejs8-nodejs-0:8.16.1-2.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 6Fixed in: jbcs-httpd24-httpd-0:2.4.29-41.jbcs.el6
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 6Fixed in: jbcs-httpd24-nghttp2-0:1.39.2-1.jbcs.el6
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 6Fixed in: jbcs-httpd24-apr-0:1.6.3-63.jbcs.el6
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 6Fixed in: jbcs-httpd24-apr-util-0:1.6.1-48.jbcs.el6
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 6Fixed in: jbcs-httpd24-brotli-0:1.0.6-7.jbcs.el6
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 6Fixed in: jbcs-httpd24-curl-0:7.64.1-14.jbcs.el6
View patch
terraformpatch availablevia llm_extracted
Fixed in: 1.17.3
dahuavendor investigatingvia llm_extracted
Fixed in: 1.16.1+
dfinityvendor investigatingvia llm_extracted
Fixed in: 1.17.3
jfrogvendor investigatingvia llm_extracted
Fixed in: 1.17.3
liferayvendor investigatingvia llm_extracted
Fixed in: 1.16.1
redhatno patchvia redhat_api
Product: Red Hat AMQ Broker 7Fixed in: jetty
redhatno patchvia redhat_api
Product: Red Hat 3scale API Management Platform 2Fixed in: nginx

Vendor Advisories (11)

microsoft2020-Nov/CVE-2019-9516

CVE-2019-9516

Nov 10, 2020
microsoft2019-Aug/CVE-2019-9516Moderate

Some HTTP/2 implementations are vulnerable to a header leak potentially leading to a denial of service

Aug 13, 2019
redhatCVE-2019-9516Important

HTTP/2: 0-length headers lead to denial of service

Aug 13, 2019
dfinityllm-dfinity-b7455d07657120fbLOW

Excessive memory usage in HTTP/2 with zero length headers

Jan 1, 2019
opensshllm-openssh-f1e14f4fff80ef6fLOW

Excessive memory usage in HTTP/2 with zero length headers

Jan 1, 2019
power_billm-power_bi-2394747aa61732efLOW

Excessive memory usage in HTTP/2 with zero length headers

Jan 1, 2019
liferayllm-liferay-f767d16091e1abccLOW

Excessive memory usage in HTTP/2 with zero length headers

Jan 1, 2019
jfrogllm-jfrog-fb22427952f54c4cLOW

Excessive memory usage in HTTP/2 with zero length headers

Jan 1, 2019
terraformllm-terraform-230ba1b576c299d1LOW

Excessive memory usage in HTTP/2 with zero length headers

dahuallm-dahua-d55a25196a4dada2LOW

Excessive memory usage in HTTP/2 with zero length headers

netgearllm-netgear-69bbbf144f7c81faLOW

Excessive memory usage in HTTP/2 with zero length headers

References

lists.opensuse.org / opensuse-security-announce/2019-09/msg00031.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2019-09/msg00032.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2019-09/msg00035.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2019-10/msg00014.html
Mailing ListThird Party Advisory
access.redhat.com / errata/RHSA-2019:2745
Third Party Advisory
access.redhat.com / errata/RHSA-2019:2746
Third Party Advisory
access.redhat.com / errata/RHSA-2019:2775
Third Party Advisory
access.redhat.com / errata/RHSA-2019:2799
Third Party Advisory
access.redhat.com / errata/RHSA-2019:2925
Third Party Advisory
access.redhat.com / errata/RHSA-2019:2939
Third Party Advisory
access.redhat.com / errata/RHSA-2019:2946
Third Party Advisory
access.redhat.com / errata/RHSA-2019:2950
Third Party Advisory
access.redhat.com / errata/RHSA-2019:2955
Third Party Advisory
access.redhat.com / errata/RHSA-2019:2966
Third Party Advisory
access.redhat.com / errata/RHSA-2019:3932
Third Party Advisory
access.redhat.com / errata/RHSA-2019:3933
Third Party Advisory
access.redhat.com / errata/RHSA-2019:3935
Third Party Advisory
seclists.org / fulldisclosure/2019/Aug/16
Mailing ListThird Party Advisory
github.com / Netflix/security-bulletins/blob/master/advisories/third-party/2019-002.md
Third Party Advisory
kb.cert.org / vuls/id/605641
Third Party AdvisoryUS Government Resource
kc.mcafee.com / corporate/index
Third Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/4ZQGHE3WTYLYAYJEIDJVF2FIGQTAYPMC
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/BP556LEG3WENHZI5TAQ6ZEBFTJB4E2IS
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/CMNFX5MNYRWWIMO4BTKYQCGUDMHO3AXP
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/H472D5HPXN6RRXCNFML3BK5OYC52CXF2
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/POPAEC4FWL4UU4LDEGPY5NPALU24FFQD
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/TAZZEVTCN2B4WT6AIBJ7XGYJMBTORJU5
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/XHTKU7YQ5EEP2XNSAV4M4VJ7QCBOJMOD
seclists.org / bugtraq/2019/Aug/24
Mailing ListThird Party Advisory
seclists.org / bugtraq/2019/Aug/40
Mailing ListThird Party Advisory
security.netapp.com / advisory/ntap-20190823-0002
Third Party Advisory
security.netapp.com / advisory/ntap-20190823-0005
Third Party Advisory
support.f5.com / csp/article/K02591030
Third Party Advisory
support.f5.com / csp/article/K02591030
usn.ubuntu.com / 4099-1
Third Party Advisory
debian.org / security/2019/dsa-4505
Third Party Advisory
synology.com / security/advisory/Synology_SA_19_33
Third Party Advisory