High severity7.5NVD Advisory· Published Aug 13, 2019· Updated Jun 17, 2026
CVE-2019-9514
CVE-2019-9514
Description
Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of streams and sends an invalid request over each stream that should solicit a stream of RST_STREAM frames from the peer. Depending on how the peer queues the RST_STREAM frames, this can consume excess memory, CPU, or both.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
golang.org/x/netGo | < 0.0.0-20190813141303-74dc4d7220e7 | 0.0.0-20190813141303-74dc4d7220e7 |
Affected products
86- cpe:2.3:a:netapp:cloud_insights:-:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:graalvm:19.2.0:*:*:*:enterprise:*:*:*
- cpe:2.3:a:redhat:developer_tools:1.0:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:jboss_core_services:1.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.2.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openshift_container_platform:3.10:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:redhat:openshift_container_platform:3.10:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_container_platform:3.11:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_container_platform:3.9:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_container_platform:4.1:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_container_platform:4.2:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_service_mesh:1.0:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:single_sign-on:7.3:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:software_collections:1.0:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*+ 2 more
- cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:19.04:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_eus:8.1:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*
- cpe:2.3:o:synology:diskstation_manager:6.2:*:*:*:*:*:*:*
- cpe:2.3:o:synology:vs960hd_firmware:-:*:*:*:*:*:*:*
- HTTP/2/HTTP/2description
- osv-coords47 versionspkg:apk/chainguard/heypkg:apk/chainguard/k3dpkg:apk/chainguard/k3d-proxypkg:apk/chainguard/k3d-toolspkg:apk/wolfi/heypkg:apk/wolfi/k3dpkg:apk/wolfi/k3d-proxypkg:apk/wolfi/k3d-toolspkg:golang/golang.org/x/netpkg:rpm/almalinux/containernetworking-pluginspkg:rpm/almalinux/containers-commonpkg:rpm/almalinux/fuse-overlayfspkg:rpm/almalinux/nodejs-nodemonpkg:rpm/almalinux/nodejs-packagingpkg:rpm/almalinux/oci-systemd-hookpkg:rpm/almalinux/oci-umountpkg:rpm/almalinux/runcpkg:rpm/almalinux/skopeopkg:rpm/opensuse/go1.11&distro=openSUSE%20Leap%2015.0pkg:rpm/opensuse/go1.11&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/go1.11&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/go1.12&distro=openSUSE%20Leap%2015.0pkg:rpm/opensuse/go1.12&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/go1.12&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/nodejs10&distro=openSUSE%20Leap%2015.0pkg:rpm/opensuse/nodejs10&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/nodejs8&distro=openSUSE%20Leap%2015.0pkg:rpm/opensuse/nodejs8&distro=openSUSE%20Leap%2015.1pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4-LTSSpkg:rpm/suse/MozillaFirefox-branding-SLED&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4-LTSSpkg:rpm/suse/firefox-atk&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4-LTSSpkg:rpm/suse/firefox-cairo&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4-LTSSpkg:rpm/suse/firefox-gdk-pixbuf&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4-LTSSpkg:rpm/suse/firefox-glib2&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4-LTSSpkg:rpm/suse/firefox-gtk3&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4-LTSSpkg:rpm/suse/firefox-harfbuzz&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4-LTSSpkg:rpm/suse/firefox-libffi&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4-LTSSpkg:rpm/suse/firefox-libffi-gcc5&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4-LTSSpkg:rpm/suse/firefox-pango&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4-LTSSpkg:rpm/suse/mozilla-nspr&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4-LTSSpkg:rpm/suse/mozilla-nss&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4-LTSSpkg:rpm/suse/nodejs10&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Web%20and%20Scripting%2012pkg:rpm/suse/nodejs10&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Web%20and%20Scripting%2015pkg:rpm/suse/nodejs10&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Web%20and%20Scripting%2015%20SP1pkg:rpm/suse/nodejs12&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Web%20and%20Scripting%2012pkg:rpm/suse/nodejs8&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Web%20and%20Scripting%2015pkg:rpm/suse/nodejs8&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Web%20and%20Scripting%2015%20SP1
< 0.1.4-r3+ 46 more
- (no CPE)range: < 0.1.4-r3
- (no CPE)range: < 5.6.0-r11
- (no CPE)range: < 5.6.0-r11
- (no CPE)range: < 5.6.0-r11
- (no CPE)range: < 0.1.4-r3
- (no CPE)range: < 5.6.0-r11
- (no CPE)range: < 5.6.0-r11
- (no CPE)range: < 5.6.0-r11
- (no CPE)range: < 0.0.0-20190813141303-74dc4d7220e7
- (no CPE)range: < 0.7.4-4.git9ebe139.module_el8.3.0+2044+12421f43
- (no CPE)range: < 1:0.1.32-6.git1715c90.module_el8.4.0+2478+12421f43
- (no CPE)range: < 0.3-5.module_el8.3.0+2044+12421f43
- (no CPE)range: < 1.18.3-1.module_el8.3.0+2023+d2377ea3
- (no CPE)range: < 17-3.module_el8.4.0+2224+b07ac28e
- (no CPE)range: < 1:0.1.15-2.git2d0b8a3.module_el8.5.0+119+9a9ec082
- (no CPE)range: < 2:2.3.4-2.git87f9237.module_el8.5.0+119+9a9ec082
- (no CPE)range: < 1.0.0-56.rc5.dev.git2abd837.module_el8.3.0+2044+12421f43
- (no CPE)range: < 1:0.1.32-6.git1715c90.module_el8.4.0+2496+12421f43
- (no CPE)range: < 1.11.13-lp151.2.9.1
- (no CPE)range: < 1.11.13-lp151.2.9.1
- (no CPE)range: < 1.11.13-10.5
- (no CPE)range: < 1.12.9-lp151.2.13.1
- (no CPE)range: < 1.12.9-lp151.2.9.1
- (no CPE)range: < 1.12.17-4.8
- (no CPE)range: < 10.16.3-lp151.2.6.1
- (no CPE)range: < 10.16.3-lp151.2.6.1
- (no CPE)range: < 8.16.1-lp151.2.6.1
- (no CPE)range: < 8.16.1-lp151.2.6.1
- (no CPE)range: < 68.2.0-78.51.4
- (no CPE)range: < 68-21.9.8
- (no CPE)range: < 2.26.1-2.8.4
- (no CPE)range: < 1.15.10-2.13.4
- (no CPE)range: < 2.36.11-2.8.4
- (no CPE)range: < 2.54.3-2.14.7
- (no CPE)range: < 3.10.9-2.15.3
- (no CPE)range: < 1.7.5-2.7.4
- (no CPE)range: < 3.2.1.git259-2.3.3
- (no CPE)range: < 5.3.1+r233831-14.1
- (no CPE)range: < 1.40.14-2.7.4
- (no CPE)range: < 4.21-29.6.1
- (no CPE)range: < 3.45-38.9.3
- (no CPE)range: < 10.16.3-1.12.1
- (no CPE)range: < 10.16.3-1.12.1
- (no CPE)range: < 10.16.3-1.12.1
- (no CPE)range: < 12.13.0-1.3.1
- (no CPE)range: < 8.16.1-3.20.1
- (no CPE)range: < 8.16.1-3.20.1
Patches
Vulnerability mechanics
References
87- lists.opensuse.org/opensuse-security-announce/2019-08/msg00076.htmlnvdMailing ListThird Party AdvisoryWEB
- lists.opensuse.org/opensuse-security-announce/2019-09/msg00002.htmlnvdMailing ListThird Party AdvisoryWEB
- lists.opensuse.org/opensuse-security-announce/2019-09/msg00011.htmlnvdMailing ListThird Party AdvisoryWEB
- lists.opensuse.org/opensuse-security-announce/2019-09/msg00021.htmlnvdMailing ListThird Party AdvisoryWEB
- lists.opensuse.org/opensuse-security-announce/2019-09/msg00031.htmlnvdMailing ListThird Party AdvisoryWEB
- lists.opensuse.org/opensuse-security-announce/2019-09/msg00032.htmlnvdMailing ListThird Party AdvisoryWEB
- lists.opensuse.org/opensuse-security-announce/2019-09/msg00038.htmlnvdMailing ListThird Party AdvisoryWEB
- seclists.org/fulldisclosure/2019/Aug/16nvdMailing ListThird Party AdvisoryWEB
- www.openwall.com/lists/oss-security/2019/08/20/1nvdMailing ListThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2019:2594nvdThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2019:2661nvdThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2019:2682nvdThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2019:2690nvdThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2019:2726nvdThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2019:2766nvdThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2019:2769nvdThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2019:2796nvdThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2019:2861nvdThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2019:2925nvdThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2019:2939nvdThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2019:2955nvdThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2019:2966nvdThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2019:3131nvdThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2019:3245nvdThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2019:3265nvdThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2019:3892nvdThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2019:3906nvdThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2019:4018nvdThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2019:4019nvdThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2019:4020nvdThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2019:4021nvdThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2019:4040nvdThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2019:4041nvdThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2019:4042nvdThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2019:4045nvdThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2019:4269nvdThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2019:4273nvdThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2019:4352nvdThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2020:0406nvdThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2020:0727nvdThird Party AdvisoryWEB
- github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-002.mdnvdThird Party AdvisoryWEB
- github.com/advisories/GHSA-39qc-96h7-956fghsaADVISORY
- kb.cert.org/vuls/id/605641/nvdThird Party AdvisoryUS Government Resource
- kc.mcafee.com/corporate/indexnvdThird Party AdvisoryWEB
- lists.debian.org/debian-lts-announce/2020/12/msg00011.htmlnvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2019-9514ghsaADVISORY
- seclists.org/bugtraq/2019/Aug/24nvdMailing ListThird Party AdvisoryWEB
- seclists.org/bugtraq/2019/Aug/31nvdMailing ListThird Party AdvisoryWEB
- seclists.org/bugtraq/2019/Aug/43nvdMailing ListThird Party AdvisoryWEB
- seclists.org/bugtraq/2019/Sep/18nvdMailing ListThird Party AdvisoryWEB
- security.netapp.com/advisory/ntap-20190823-0001/nvdThird Party Advisory
- security.netapp.com/advisory/ntap-20190823-0004/nvdThird Party Advisory
- security.netapp.com/advisory/ntap-20190823-0005/nvdThird Party Advisory
- support.f5.com/csp/article/K01988340nvdThird Party AdvisoryWEB
- usn.ubuntu.com/4308-1/nvdThird Party Advisory
- www.debian.org/security/2019/dsa-4503nvdThird Party AdvisoryWEB
- www.debian.org/security/2019/dsa-4508nvdThird Party AdvisoryWEB
- www.debian.org/security/2019/dsa-4520nvdThird Party AdvisoryWEB
- www.debian.org/security/2020/dsa-4669nvdThird Party AdvisoryWEB
- www.synology.com/security/advisory/Synology_SA_19_33nvdThird Party AdvisoryWEB
- www.openwall.com/lists/oss-security/2023/10/18/8nvdWEB
- go.dev/cl/190137ghsaWEB
- go.dev/issue/33606ghsaWEB
- go.googlesource.com/go/+/145e193131eb486077b66009beb051aba07c52a5ghsaWEB
- groups.google.com/g/golang-announce/c/65QixT3tcmg/m/DrFiG6vvCwAJghsaWEB
- kb.cert.org/vuls/id/605641ghsaWEB
- lists.apache.org/thread.html/392108390cef48af647a2e47b7fd5380e050e35ae8d1aa2030254c04@%3Cusers.trafficserver.apache.org%3EghsaWEB
- lists.apache.org/thread.html/ad3d01e767199c1aed8033bb6b3f5bf98c011c7c536f07a5d34b3c19@%3Cannounce.trafficserver.apache.org%3EghsaWEB
- lists.apache.org/thread.html/bde52309316ae798186d783a5e29f4ad1527f61c9219a289d0eee0a7@%3Cdev.trafficserver.apache.org%3EghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/4BBP27PZGSY6OP6D26E5FW4GZKBFHNU7ghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/4ZQGHE3WTYLYAYJEIDJVF2FIGQTAYPMCghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/CMNFX5MNYRWWIMO4BTKYQCGUDMHO3AXPghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/LYO6E3H34C346D2E443GLXK7OK6KIYIQghsaWEB
- pkg.go.dev/vuln/GO-2022-0536ghsaWEB
- security.netapp.com/advisory/ntap-20190823-0001ghsaWEB
- security.netapp.com/advisory/ntap-20190823-0004ghsaWEB
- security.netapp.com/advisory/ntap-20190823-0005ghsaWEB
- support.f5.com/csp/article/K01988340ghsaWEB
- usn.ubuntu.com/4308-1ghsaWEB
- lists.apache.org/thread.html/392108390cef48af647a2e47b7fd5380e050e35ae8d1aa2030254c04%40%3Cusers.trafficserver.apache.org%3Envd
- lists.apache.org/thread.html/ad3d01e767199c1aed8033bb6b3f5bf98c011c7c536f07a5d34b3c19%40%3Cannounce.trafficserver.apache.org%3Envd
- lists.apache.org/thread.html/bde52309316ae798186d783a5e29f4ad1527f61c9219a289d0eee0a7%40%3Cdev.trafficserver.apache.org%3Envd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4BBP27PZGSY6OP6D26E5FW4GZKBFHNU7/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4ZQGHE3WTYLYAYJEIDJVF2FIGQTAYPMC/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CMNFX5MNYRWWIMO4BTKYQCGUDMHO3AXP/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LYO6E3H34C346D2E443GLXK7OK6KIYIQ/nvd
- support.f5.com/csp/article/K01988340nvd
News mentions
0No linked articles in our index yet.