Vulnerability record · CVE-2019-9511 · published 13 August 2019
CVE-2019-9511: HTTP/2 window size and stream priority manipulation denial of service
Apple · Swiftnio
Multiple HTTP/2 implementations mishandle window size and stream prioritization, letting an attacker request a large resource across many streams and force the server to queue data in 1-byte chunks. This uncontrolled resource consumption can exhaust CPU, memory, or both, degrading or taking down the HTTP/2 service. It affects a broad set of vendors and products, so exposure depends on which HTTP/2 stacks are deployed.
Description
Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service. The attacker requests a large amount of data from a specified resource over multiple streams. They manipulate window size and stream priority to force the server to queue the data in 1-byte chunks. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
high priorityCVSS 7.5 with network reachability, no authentication, and high EPSS make this a serious availability threat despite no KEV listing.
What it is
Multiple HTTP/2 implementations mishandle window size and stream prioritization, letting an attacker request a large resource across many streams and force the server to queue data in 1-byte chunks. This uncontrolled resource consumption can exhaust CPU, memory, or both, degrading or taking down the HTTP/2 service. It affects a broad set of vendors and products, so exposure depends on which HTTP/2 stacks are deployed.
Impact
An unauthenticated remote attacker can consume excessive server CPU and memory, causing denial of service for legitimate users. No data confidentiality or integrity impact is described; the effect is availability loss.
Attack surface
Reachable over the network via HTTP/2 requests to a vulnerable server; the CVSS vector shows no privileges and no user interaction required. Any exposed HTTP/2 endpoint running an affected implementation is a candidate target.
Exploitation
Not listed in CISA KEV and no ransomware usage documented, but EPSS is high (0.595 probability, 99th percentile), indicating elevated likelihood of exploitation activity. References are vendor advisories and a Netflix third-party bulletin, with no public exploit tag supplied.
What to do
- Patch or upgrade affected HTTP/2 implementations to vendor-fixed versions listed in the referenced advisories (Red Hat, openSUSE, Netflix bulletin, and others).
- Where immediate patching is not possible, limit or disable HTTP/2 on internet-facing services, or cap concurrent streams and request sizes at the load balancer or reverse proxy.
- Apply rate limiting and connection/stream concurrency limits per client to reduce the ability to open many streams against a single resource.
- Monitor and tune server memory and CPU limits so a single abusive client cannot exhaust shared resources.
- Review exposure of all listed products (nginx, Node.js, Apache Traffic Server, JBoss, F5, Synology, and others) and prioritize internet-facing instances.
Detection
- Alert on single clients opening unusually high numbers of concurrent HTTP/2 streams or repeatedly requesting the same large resource.
- Monitor server CPU and memory spikes correlated with HTTP/2 traffic from one source or connection.
- Log and review HTTP/2 window update and priority frame patterns for anomalies, such as many tiny data chunks.
- Track HTTP/2 connection counts and stream resets per client IP to spot resource-exhaustion attempts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
20 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2019-9511 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-9511), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.