[NGINX:CVE-2019-9513] Excessive CPU usage in HTTP/2 with priority changes

Severity Low
Affected Packages 1
Unaffected Packages 2
CVEs 1

Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service. The attacker creates multiple request streams and continually shuffles the priority of the streams in a way that causes substantial churn to the priority tree. This can consume excess CPU.

Package Affected Version
pkg:nginx/nginx >= 1.9.5, <= 1.17.2
Package Unaffected Version
pkg:nginx/nginx >= 1.17.3
pkg:nginx/nginx >= 1.16.1
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:nginx/nginx nginx >= 1.9.5 <= 1.17.2
Unaffected pkg:nginx/nginx nginx >= 1.17.3
Unaffected pkg:nginx/nginx nginx >= 1.16.1
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date