CVE-2019-9512High· 7.5▾ TwilightSome HTTP/2 implementations are vulnerable to ping floods, potentially leading to a denial of service. The attacker sends continual pings to an HTTP/2 peer, causing the peer to build an internal queue of responses. Depending on how effic…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 16.7 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
83%
Some HTTP/2 implementations are vulnerable to ping floods, potentially leading to a denial of service. The attacker sends continual pings to an HTTP/2 peer, causing the peer to build an internal queue of responses. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both.
swiftnio >= 1.0.0, <= 1.4.0traffic_server >= 6.0.0, <= 6.2.3traffic_server >= 7.0.0, <= 7.1.6traffic_server >= 8.0.0, <= 8.0.3debian_linux = 10.0node.js >= 8.0.0, <= 8.8.1node.js >= 8.9.0, < 8.16.1node.js >= 10.0.0, <= 10.12.0node.js >= 10.13.0, < 10.16.3node.js >= 12.0.0, < 12.8.1Upgrade past the affected range:
node.js 12.8.1Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-20652High· 7.5The issue was addressed with improved memory handling
CVE-2026-84553High· 7.5A resource exhaustion issue was addressed with improved input validation
CVE-2026-65388High· 7.5A remote attacker who controls a container registry may be able to direct a client's token request to a host of the attacker's choice, and disclose the victim's registry credentials to that host
CVE-2026-84624Medium· 5.5A permissions issue was addressed with improved path validation
CVE-2026-84576Medium· 5.5This issue was addressed with improved checks
CVE-2026-84632High· 7.3The issue was addressed with improved memory handling