Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2019-9517

31
FAUCET Score

CVE-2019-9517 describes a denial-of-service vulnerability in various HTTP/2 implementations, including products from Apache, Apple, Node.js, and Oracle. Attackers can exploit this by manipulating HTTP/2 and TCP windows to force servers to buffer large response objects, consuming excessive memory or CPU. With a CVSS score of 7.5 (HIGH), this network-exploitable vulnerability requires no user interaction and can lead to a complete loss of availability. While there are no known public exploits or Metasploit modules, the vulnerability has garnered significant community discussion and media coverage, indicating awareness despite not being on CISA's KEV catalog.

Impacted Technologies

VendorProductVersion(s)CPE
>= 1.0.0, <= 1.4.0CPE matchmatch criteria
cpe:2.3:a:apple:swiftnio:*:*:*:*:*:*:*:*
>= 2.4.20, < 2.4.40CPE matchmatch criteria
cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*
>= 6.0.0, <= 6.2.3CPE matchmatch criteria
cpe:2.3:a:apache:traffic_server:*:*:*:*:*:*:*:*
>= 7.0.0, <= 7.1.6CPE matchmatch criteria
cpe:2.3:a:apache:traffic_server:*:*:*:*:*:*:*:*
>= 8.0.0, <= 8.0.3CPE matchmatch criteria
cpe:2.3:a:apache:traffic_server:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

7.5HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.0

Exploit Intelligence

EPSS Score
27.00%
Probability of exploitation in next 30 days
EPSS Percentile
97.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.2700 is in the 96th percentile among its peer group of 51,506 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (63)

apachepatch availablevia llm_extracted
Fixed in: 2.4
oraclepatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 6Fixed in: jbcs-httpd24-nghttp2-0:1.39.2-1.jbcs.el6
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 6Fixed in: jbcs-httpd24-apr-0:1.6.3-63.jbcs.el6
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 6Fixed in: jbcs-httpd24-apr-util-0:1.6.1-48.jbcs.el6
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 6Fixed in: jbcs-httpd24-brotli-0:1.0.6-7.jbcs.el6
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 6Fixed in: jbcs-httpd24-curl-0:7.64.1-14.jbcs.el6
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 6Fixed in: jbcs-httpd24-httpd-0:2.4.37-33.jbcs.el6
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 6Fixed in: jbcs-httpd24-jansson-0:2.11-20.jbcs.el6
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 6Fixed in: jbcs-httpd24-mod_cluster-native-0:1.3.12-9.Final_redhat_2.jbcs.el6
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 6Fixed in: jbcs-httpd24-mod_jk-0:1.2.46-22.redhat_1.jbcs.el6
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 6Fixed in: jbcs-httpd24-mod_security-0:2.9.2-16.GA.jbcs.el6
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 6Fixed in: jbcs-httpd24-nghttp2-0:1.39.2-4.jbcs.el6
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 6Fixed in: jbcs-httpd24-openssl-1:1.1.1-25.jbcs.el6
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-httpd-0:2.4.29-41.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-nghttp2-0:1.39.2-1.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-apr-0:1.6.3-63.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-apr-util-0:1.6.1-48.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-brotli-0:1.0.6-7.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-curl-0:7.64.1-14.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-httpd-0:2.4.37-33.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-jansson-0:2.11-20.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-mod_cluster-native-0:1.3.12-9.Final_redhat_2.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-mod_jk-0:1.2.46-22.redhat_1.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-mod_security-0:2.9.2-16.GA.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-nghttp2-0:1.39.2-4.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-openssl-1:1.1.1-25.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat AMQ
View patch
redhatpatch availablevia redhat_api
Product: Red Hat AMQ 7.4.3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: httpd:2.4-8000020190829150747.f8e95b4e
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: nodejs:10-8000020190911085529.f8e95b4e
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Fuse 7.6.0Fixed in: undertow
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 6Fixed in: httpd24-httpd-0:2.4.34-8.el6.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 6Fixed in: httpd24-nghttp2-0:1.7.1-7.el6.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7Fixed in: rh-nodejs10-0:3.2-3.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7Fixed in: rh-nodejs10-nodejs-0:10.16.3-3.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7Fixed in: httpd24-httpd-0:2.4.34-8.el7.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7Fixed in: httpd24-nghttp2-0:1.7.1-7.el7.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7Fixed in: rh-nodejs8-0:3.0-5.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7Fixed in: rh-nodejs8-nodejs-0:8.16.1-2.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUSFixed in: rh-nodejs10-0:3.2-3.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUSFixed in: rh-nodejs10-nodejs-0:10.16.3-3.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUSFixed in: httpd24-httpd-0:2.4.34-8.el7.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUSFixed in: httpd24-nghttp2-0:1.7.1-7.el7.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUSFixed in: rh-nodejs8-0:3.0-5.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUSFixed in: rh-nodejs8-nodejs-0:8.16.1-2.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUSFixed in: rh-nodejs10-0:3.2-3.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUSFixed in: httpd24-httpd-0:2.4.34-8.el7.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUSFixed in: httpd24-nghttp2-0:1.7.1-7.el7.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUSFixed in: rh-nodejs8-0:3.0-5.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUSFixed in: rh-nodejs8-nodejs-0:8.16.1-2.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUSFixed in: rh-nodejs10-0:3.2-3.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUSFixed in: rh-nodejs10-nodejs-0:10.16.3-3.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUSFixed in: httpd24-httpd-0:2.4.34-8.el7.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUSFixed in: httpd24-nghttp2-0:1.7.1-7.el7.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUSFixed in: rh-nodejs8-0:3.0-5.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUSFixed in: rh-nodejs8-nodejs-0:8.16.1-2.el7
View patch
redhatpatch availablevia redhat_api
Product: Text-Only JBCSFixed in: mod_http2
View patch
redhatpatch availablevia redhat_api
Product: Text-Only JBCS
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUSFixed in: rh-nodejs10-nodejs-0:10.16.3-3.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 6Fixed in: jbcs-httpd24-httpd-0:2.4.29-41.jbcs.el6
View patch
redhatno patchvia redhat_api
Product: Red Hat AMQ Broker 7Fixed in: jetty
redhatno patchvia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7Fixed in: undertow-core

Vendor Advisories (4)

apachellm-apache-f398f8ed28802aa3LOW

Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project

Mar 2, 2026
apachellm-apache-a7a91ec4c0e9421dHIGH

Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project

Dec 10, 2025
redhatCVE-2019-9517Important

HTTP/2: request for large response leads to denial of service

Aug 13, 2019
apachellm-apache-684e4d0003611bd4LOW

Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project

References

lists.opensuse.org / opensuse-security-announce/2019-09/msg00004.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2019-09/msg00031.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2019-09/msg00032.html
Mailing ListThird Party Advisory
access.redhat.com / errata/RHSA-2019:2893
Third Party Advisory
access.redhat.com / errata/RHSA-2019:2925
Third Party Advisory
access.redhat.com / errata/RHSA-2019:2939
Third Party Advisory
access.redhat.com / errata/RHSA-2019:2946
Third Party Advisory
access.redhat.com / errata/RHSA-2019:2949
Third Party Advisory
access.redhat.com / errata/RHSA-2019:2950
Third Party Advisory
access.redhat.com / errata/RHSA-2019:2955
Third Party Advisory
access.redhat.com / errata/RHSA-2019:3932
Third Party Advisory
access.redhat.com / errata/RHSA-2019:3933
Third Party Advisory
access.redhat.com / errata/RHSA-2019:3935
Third Party Advisory
github.com / Netflix/security-bulletins/blob/master/advisories/third-party/2019-002.md
Third Party Advisory
kb.cert.org / vuls/id/605641
Third Party AdvisoryUS Government Resource
kc.mcafee.com / corporate/index
Third Party Advisory
lists.apache.org / thread.html/4610762456644181b267c846423b3a990bd4aaea1886ecc7d51febdb%40%3Cannounce.httpd.apache.org%3E
lists.apache.org / thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/d89f999e26dfb1d50f247ead1fe8538014eb412b2dbe5be4b1a9ef50%40%3Cdev.httpd.apache.org%3E
lists.apache.org / thread.html/ec97fdfc1a859266e56fef084353a34e0a0b08901b3c1aa317a43c8c%40%3Cdev.httpd.apache.org%3E
lists.apache.org / thread.html/r03ee478b3dda3e381fd6189366fa7af97c980d2f602846eef935277d%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/r06f0d87ebb6d59ed8379633f36f72f5b1f79cadfda72ede0830b42cf%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/r3c5c3104813c1c5508b55564b66546933079250a46ce50eee90b2e36%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/r76142b8c5119df2178be7c2dba88fde552eedeec37ea993dfce68d1d%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/rc998b18880df98bafaade071346690c2bc1444adaa1a1ea464b93f0a%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0456cc582390b6f%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/rd2fb621142e7fa187cfe12d7137bf66e7234abcbbcd800074c84a538%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/re3d27b6250aa8548b8845d314bb8a350b3df326cacbbfdfe4d455234%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/4ZQGHE3WTYLYAYJEIDJVF2FIGQTAYPMC
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/BP556LEG3WENHZI5TAQ6ZEBFTJB4E2IS
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/CMNFX5MNYRWWIMO4BTKYQCGUDMHO3AXP
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/XHTKU7YQ5EEP2XNSAV4M4VJ7QCBOJMOD
seclists.org / bugtraq/2019/Aug/47
Mailing ListThird Party Advisory
security.gentoo.org / glsa/201909-04
Third Party Advisory
security.netapp.com / advisory/ntap-20190823-0003
Third Party Advisory
security.netapp.com / advisory/ntap-20190823-0005
Third Party Advisory
security.netapp.com / advisory/ntap-20190905-0003
Third Party Advisory
support.f5.com / csp/article/K02591030
Third Party Advisory
support.f5.com / csp/article/K02591030
usn.ubuntu.com / 4113-1
Third Party Advisory
debian.org / security/2019/dsa-4509
Third Party Advisory
oracle.com / security-alerts/cpuapr2020.html
Third Party Advisory
oracle.com / technetwork/security-advisory/cpuoct2019-5072832.html
PatchThird Party Advisory
synology.com / security/advisory/Synology_SA_19_33
Third Party Advisory
openwall.com / lists/oss-security/2019/08/15/7
Mailing ListThird Party Advisory