VYPR
High severity7.5NVD Advisory· Published Oct 22, 2019· Updated Jun 17, 2026

CVE-2019-10079

CVE-2019-10079

Description

Apache Traffic Server is vulnerable to HTTP/2 setting flood attacks. Earlier versions of Apache Traffic Server didn't limit the number of setting frames sent from the client using the HTTP/2 protocol. Users should upgrade to Apache Traffic Server 7.1.7, 8.0.4, or later versions.

Affected products

3
  • cpe:2.3:a:apache:traffic_server:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:apache:traffic_server:*:*:*:*:*:*:*:*range: <7.1.7
    • (no CPE)range: 7.1.7, 8.0.4, or later
  • Apache/Traffic Serverdescription

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.