Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

This table lists vendors and products affected by a set of vulnerabilities in multiple HTTP/2 implementations. For more information see vul note and researcher doc VU#605641 and NFLX-2019-002.

Matrix

Apache
VendorProductVersion

Affected Versions

Data Dribble
CVE-2019-9511

Ping Flood
CVE-2019-9512

Resource Loop
CVE-2019-9513

Reset Flood
CVE-2019-9514

Settings Flood
CVE-2019-9515

0-Length Headers Leak
CVE-2019-9516

Internal Data Buffering
CVE-2019-9517

Empty Frames Flood
CVE-2019-9518

F5NGINX1.15.8

Affected

Addressed in

NYNNYNN
Go 1.12 (before Go 1.11.13 and Go 1.12.8)

NYNYNNNN
Netty ProjectNetty4.1.27Not affected

Affected

https://netty.io/news/2019/08/13/4-1-39-Final.html

Not affected

Affected

https://netty.io/news/2019/08/13/4-1-39-Final.html

Affected

https://netty.io/news/2019/08/13/4-1-39-Final.html
Not affectedNot affected

Affected

https://netty.io/news/2019/08/13/4-1-39-Final.html
Apache 2.4.38
NYNYY2.4.38NNN
NNY
Apache Tomcat 9.0.13 (w/ FreeBSD native library 1.2.16)

NNBorderlineNNN

node.js 11.11.0 + libnghttp2 1.35.1

YNYYNY/NN
Microsoft IIS

YYYYNNNY
gRPC C 1.21.0

NNNYYNN
gRPC Java 1.21.0 (uses Netty)

NNNNYNN
gRPC Go 1.21.0

NNNYYNN
swift-nio-http2 1.0.0, 1.0.1, 1.1.0, 1.2.0, 1.2.1, 1.3.0, 1.4.0

NYNYYYNY
hyper-2 (Python)

NNNNNN

Twisted  16.3.0, 16.3.1, 16.3.2, 16.4.0, 16.4.1, 16.5.0, 16.6.0, 17.1.0, 17.5.0, 17.9.0, 18.4.0, 18.7.0, 18.9.0, 19.2.0, 19.2.1, 19.7.0

NYNYNNN
nghttp2

YNYNNNN
Apache Traffic Server

NYNYYNN
EnvoyEnvoyPrior (all versions prior to 1.11.1)NYYYYNNNot affected

Affected

https://groups.google.com/forum/#!topic/envoy-announce/ZLchtraPYVk

Affected

https://groups.google.com/forum/#!topic/envoy-announce/ZLchtraPYVk

Affected

https://groups.google.com/forum/#!topic/envoy-announce/ZLchtraPYVk

Affected

https://groups.google.com/forum/#!topic/envoy-announce/ZLchtraPYVk
Not affectedNot affected

Affected

https://groups.google.com/forum/#!topic/envoy-announce/ZLchtraPYVkY
proxygen

NYYYYNN

References


Other References

https://blog.cloudflare.com/on-the-recent-http-2-dos-attacks/some urls?