Lucene search

K
osvGoogleOSV:CVE-2019-9513
HistoryAug 13, 2019 - 9:15 p.m.

CVE-2019-9513

2019-08-1321:15:12
Google
osv.dev
9

6.9 Medium

AI Score

Confidence

Low

0.054 Low

EPSS

Percentile

93.2%

Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service. The attacker creates multiple request streams and continually shuffles the priority of the streams in a way that causes substantial churn to the priority tree. This can consume excess CPU.

References