---
id: CVE-2019-9512
title: >-
  Some HTTP/2 implementations are vulnerable to ping floods, potentially leading
  to a denial of service
summary: >-
  Some HTTP/2 implementations are vulnerable to ping floods, potentially leading
  to a denial of service. The attacker sends continual pings to an HTTP/2 peer,
  causing the peer to build an internal queue of responses. Depending on how
  effic…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-400
vendor: apple
product: swiftnio
affected:
  - 'swiftnio >= 1.0.0, <= 1.4.0'
  - 'traffic_server >= 6.0.0, <= 6.2.3'
  - 'traffic_server >= 7.0.0, <= 7.1.6'
  - 'traffic_server >= 8.0.0, <= 8.0.3'
  - debian_linux = 10.0
  - 'node.js >= 8.0.0, <= 8.8.1'
  - 'node.js >= 8.9.0, < 8.16.1'
  - 'node.js >= 10.0.0, <= 10.12.0'
  - 'node.js >= 10.13.0, < 10.16.3'
  - 'node.js >= 12.0.0, < 12.8.1'
patched:
  - node.js 12.8.1
published: '2019-08-13'
updated: '2026-06-17'
sourceUpdated: '2026-06-17T02:43:51.673'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2019-9512'
references:
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00076.html'
    label: cret@cert.org
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00002.html'
    label: cret@cert.org
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00011.html'
    label: cret@cert.org
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00021.html'
    label: cret@cert.org
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00031.html'
    label: cret@cert.org
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00032.html'
    label: cret@cert.org
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00038.html'
    label: cret@cert.org
  - url: 'http://seclists.org/fulldisclosure/2019/Aug/16'
    label: cret@cert.org
  - url: 'http://www.openwall.com/lists/oss-security/2019/08/20/1'
    label: cret@cert.org
  - url: 'https://access.redhat.com/errata/RHSA-2019:2594'
    label: cret@cert.org
  - url: 'https://access.redhat.com/errata/RHSA-2019:2661'
    label: cret@cert.org
  - url: 'https://access.redhat.com/errata/RHSA-2019:2682'
    label: cret@cert.org
  - url: 'https://access.redhat.com/errata/RHSA-2019:2690'
    label: cret@cert.org
  - url: 'https://access.redhat.com/errata/RHSA-2019:2726'
    label: cret@cert.org
  - url: 'https://access.redhat.com/errata/RHSA-2019:2766'
    label: cret@cert.org
  - url: 'https://access.redhat.com/errata/RHSA-2019:2769'
    label: cret@cert.org
  - url: 'https://access.redhat.com/errata/RHSA-2019:2796'
    label: cret@cert.org
  - url: 'https://access.redhat.com/errata/RHSA-2019:2861'
    label: cret@cert.org
  - url: 'https://access.redhat.com/errata/RHSA-2019:2925'
    label: cret@cert.org
  - url: 'https://access.redhat.com/errata/RHSA-2019:2939'
    label: cret@cert.org
  - url: 'https://access.redhat.com/errata/RHSA-2019:2955'
    label: cret@cert.org
  - url: 'https://access.redhat.com/errata/RHSA-2019:2966'
    label: cret@cert.org
  - url: 'https://access.redhat.com/errata/RHSA-2019:3131'
    label: cret@cert.org
  - url: 'https://access.redhat.com/errata/RHSA-2019:3245'
    label: cret@cert.org
  - url: 'https://access.redhat.com/errata/RHSA-2019:3265'
    label: cret@cert.org
  - url: 'https://access.redhat.com/errata/RHSA-2019:3892'
    label: cret@cert.org
  - url: 'https://access.redhat.com/errata/RHSA-2019:3906'
    label: cret@cert.org
  - url: 'https://access.redhat.com/errata/RHSA-2019:4018'
    label: cret@cert.org
  - url: 'https://access.redhat.com/errata/RHSA-2019:4019'
    label: cret@cert.org
  - url: 'https://access.redhat.com/errata/RHSA-2019:4020'
    label: cret@cert.org
  - url: 'https://access.redhat.com/errata/RHSA-2019:4021'
    label: cret@cert.org
  - url: 'https://access.redhat.com/errata/RHSA-2019:4040'
    label: cret@cert.org
  - url: 'https://access.redhat.com/errata/RHSA-2019:4041'
    label: cret@cert.org
  - url: 'https://access.redhat.com/errata/RHSA-2019:4042'
    label: cret@cert.org
  - url: 'https://access.redhat.com/errata/RHSA-2019:4045'
    label: cret@cert.org
  - url: 'https://access.redhat.com/errata/RHSA-2019:4269'
    label: cret@cert.org
  - url: 'https://access.redhat.com/errata/RHSA-2019:4273'
    label: cret@cert.org
  - url: 'https://access.redhat.com/errata/RHSA-2019:4352'
    label: cret@cert.org
  - url: 'https://access.redhat.com/errata/RHSA-2020:0406'
    label: cret@cert.org
  - url: 'https://access.redhat.com/errata/RHSA-2020:0727'
    label: cret@cert.org
  - url: >-
      https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-002.md
    label: cret@cert.org
  - url: 'https://kb.cert.org/vuls/id/605641/'
    label: cret@cert.org
  - url: 'https://kc.mcafee.com/corporate/index?page=content&id=SB10296'
    label: cret@cert.org
  - url: >-
      https://lists.apache.org/thread.html/392108390cef48af647a2e47b7fd5380e050e35ae8d1aa2030254c04%40%3Cusers.trafficserver.apache.org%3E
    label: cret@cert.org
  - url: >-
      https://lists.apache.org/thread.html/ad3d01e767199c1aed8033bb6b3f5bf98c011c7c536f07a5d34b3c19%40%3Cannounce.trafficserver.apache.org%3E
    label: cret@cert.org
  - url: >-
      https://lists.apache.org/thread.html/bde52309316ae798186d783a5e29f4ad1527f61c9219a289d0eee0a7%40%3Cdev.trafficserver.apache.org%3E
    label: cret@cert.org
  - url: 'https://lists.debian.org/debian-lts-announce/2020/12/msg00011.html'
    label: cret@cert.org
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4BBP27PZGSY6OP6D26E5FW4GZKBFHNU7/
    label: cret@cert.org
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4ZQGHE3WTYLYAYJEIDJVF2FIGQTAYPMC/
    label: cret@cert.org
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CMNFX5MNYRWWIMO4BTKYQCGUDMHO3AXP/
    label: cret@cert.org
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LYO6E3H34C346D2E443GLXK7OK6KIYIQ/
    label: cret@cert.org
  - url: 'https://seclists.org/bugtraq/2019/Aug/24'
    label: cret@cert.org
  - url: 'https://seclists.org/bugtraq/2019/Aug/31'
    label: cret@cert.org
  - url: 'https://seclists.org/bugtraq/2019/Aug/43'
    label: cret@cert.org
  - url: 'https://seclists.org/bugtraq/2019/Sep/18'
    label: cret@cert.org
  - url: 'https://security.netapp.com/advisory/ntap-20190823-0001/'
    label: cret@cert.org
  - url: 'https://security.netapp.com/advisory/ntap-20190823-0004/'
    label: cret@cert.org
  - url: 'https://security.netapp.com/advisory/ntap-20190823-0005/'
    label: cret@cert.org
  - url: 'https://support.f5.com/csp/article/K98053339'
    label: cret@cert.org
  - url: >-
      https://support.f5.com/csp/article/K98053339?utm_source=f5support&amp%3Butm_medium=RSS
    label: cret@cert.org
  - url: 'https://usn.ubuntu.com/4308-1/'
    label: cret@cert.org
  - url: 'https://www.debian.org/security/2019/dsa-4503'
    label: cret@cert.org
  - url: 'https://www.debian.org/security/2019/dsa-4508'
    label: cret@cert.org
  - url: 'https://www.debian.org/security/2019/dsa-4520'
    label: cret@cert.org
  - url: 'https://www.synology.com/security/advisory/Synology_SA_19_33'
    label: cret@cert.org
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00076.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00002.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00011.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00021.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00031.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00032.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00038.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://seclists.org/fulldisclosure/2019/Aug/16'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2019/08/20/1'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2019:2594'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2019:2661'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2019:2682'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2019:2690'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2019:2726'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2019:2766'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2019:2769'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2019:2796'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2019:2861'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2019:2925'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2019:2939'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2019:2955'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2019:2966'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2019:3131'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2019:3245'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2019:3265'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2019:3892'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2019:3906'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2019:4018'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2019:4019'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2019:4020'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2019:4021'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2019:4040'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2019:4041'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2019:4042'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2019:4045'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2019:4269'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2019:4273'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2019:4352'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2020:0406'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2020:0727'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-002.md
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://kb.cert.org/vuls/id/605641/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://kc.mcafee.com/corporate/index?page=content&id=SB10296'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/392108390cef48af647a2e47b7fd5380e050e35ae8d1aa2030254c04%40%3Cusers.trafficserver.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/ad3d01e767199c1aed8033bb6b3f5bf98c011c7c536f07a5d34b3c19%40%3Cannounce.trafficserver.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/bde52309316ae798186d783a5e29f4ad1527f61c9219a289d0eee0a7%40%3Cdev.trafficserver.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2020/12/msg00011.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4BBP27PZGSY6OP6D26E5FW4GZKBFHNU7/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4ZQGHE3WTYLYAYJEIDJVF2FIGQTAYPMC/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CMNFX5MNYRWWIMO4BTKYQCGUDMHO3AXP/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LYO6E3H34C346D2E443GLXK7OK6KIYIQ/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://seclists.org/bugtraq/2019/Aug/24'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://seclists.org/bugtraq/2019/Aug/31'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://seclists.org/bugtraq/2019/Aug/43'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://seclists.org/bugtraq/2019/Sep/18'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20190823-0001/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20190823-0004/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20190823-0005/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://support.f5.com/csp/article/K98053339'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://support.f5.com/csp/article/K98053339?utm_source=f5support&amp%3Butm_medium=RSS
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://usn.ubuntu.com/4308-1/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.debian.org/security/2019/dsa-4503'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.debian.org/security/2019/dsa-4508'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.debian.org/security/2019/dsa-4520'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.synology.com/security/advisory/Synology_SA_19_33'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-14T13:51:46.827Z'
epss: 0.83433
epssPercentile: 0.99668
---

## Overview

Some HTTP/2 implementations are vulnerable to ping floods, potentially leading to a denial of service. The attacker sends continual pings to an HTTP/2 peer, causing the peer to build an internal queue of responses. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both.

## Affected

- `swiftnio >= 1.0.0, <= 1.4.0`
- `traffic_server >= 6.0.0, <= 6.2.3`
- `traffic_server >= 7.0.0, <= 7.1.6`
- `traffic_server >= 8.0.0, <= 8.0.3`
- `debian_linux = 10.0`
- `node.js >= 8.0.0, <= 8.8.1`
- `node.js >= 8.9.0, < 8.16.1`
- `node.js >= 10.0.0, <= 10.12.0`
- `node.js >= 10.13.0, < 10.16.3`
- `node.js >= 12.0.0, < 12.8.1`

## Remediation

Upgrade past the affected range:

- `node.js 12.8.1`
