Vulnerability record · CVE-2019-9514 · published 13 August 2019
CVE-2019-9514: HTTP/2 reset flood causes denial of service
Apple · Swiftnio
Some HTTP/2 implementations mishandle a flood of RST_STREAM frames triggered by opening many streams and sending an invalid request on each. Depending on how the peer queues those frames, memory, CPU, or both are consumed excessively, leading to denial of service. The flaw is a resource-exhaustion issue in the HTTP/2 protocol handling of multiple vendors' products.
Description
Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of streams and sends an invalid request over each stream that should solicit a stream of RST_STREAM frames from the peer. Depending on how the peer queues the RST_STREAM frames, this can consume excess memory, CPU, or both.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
high priorityHigh CVSS (7.5) availability impact with no authentication required and very high EPSS, though no KEV listing or known ransomware use.
What it is
Some HTTP/2 implementations mishandle a flood of RST_STREAM frames triggered by opening many streams and sending an invalid request on each. Depending on how the peer queues those frames, memory, CPU, or both are consumed excessively, leading to denial of service. The flaw is a resource-exhaustion issue in the HTTP/2 protocol handling of multiple vendors' products.
Impact
An attacker can exhaust server memory and CPU, degrading or halting HTTP/2 service for legitimate users. There is no confidentiality or integrity impact; the effect is availability loss.
Attack surface
Reachable over the network via the HTTP/2 protocol; the CVSS vector shows no privileges and no user interaction required. Any exposed HTTP/2 endpoint running an affected implementation is a candidate target.
Exploitation
Not listed in CISA KEV and no ransomware association is documented, but EPSS is very high (0.828, 99.7th percentile), indicating elevated likelihood of attempted exploitation. References are advisories and mailing lists, with no public exploit tag supplied.
What to do
- Apply vendor patches or errata for affected HTTP/2 implementations (Red Hat, SUSE, Debian, Ubuntu, Apache, Node.js, F5, and others listed).
- Where patching is delayed, limit or disable HTTP/2 on internet-facing services and fall back to HTTP/1.1.
- Enforce HTTP/2 stream and concurrent-stream limits and rate-limit RST_STREAM generation at the edge or proxy.
- Monitor and cap per-connection memory and CPU usage for HTTP/2 handlers to contain flood effects.
- Review vendor advisories for the specific product version in use before assuming exposure.
Detection
- Alert on spikes in RST_STREAM frames or rapid stream creation per connection in HTTP/2 traffic.
- Monitor server memory and CPU anomalies correlated with HTTP/2 connection counts.
- Log and baseline per-client HTTP/2 stream open/close ratios to spot reset-flood patterns.
- Watch for repeated invalid requests across many streams from a single source.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
28 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2019-9514 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-9514), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.