Related Vulnerabilities: CVE-2019-9513  

An issue has been found in several HTTP/2 implementations, where the attacker creates multiple request streams and continually shuffles the priority of the streams in a way that causes substantial churn to the priority tree. This can consume excess CPU, potentially leading to a denial of service.

Severity Medium

Remote Yes

Type Denial of service

Description

An issue has been found in several HTTP/2 implementations, where the attacker creates multiple request streams and continually shuffles the priority of the streams in a way that causes substantial churn to the priority tree. This can consume excess CPU, potentially leading to a denial of service.

AVG-1024 libnghttp2 1.39.1-1 Medium Vulnerable

AVG-1023 nginx 1.16.0-1 Medium Vulnerable

AVG-1022 nginx-mainline 1.17.1-1 Medium Vulnerable

https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-002.md