{"id":"GHSA-32gv-6cf3-wcmq","aliases":[],"url":"https://o3.security/vulnerability/GHSA-32gv-6cf3-wcmq","summary":"HTTP/2 DoS Attacks: Ping, Reset, and Settings Floods","details":"### Impact\nTwisted web servers that utilize the optional HTTP/2 support suffer from the following flow-control related vulnerabilities:\n\nPing flood: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9512\nReset flood: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9514\nSettings flood: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9515\n\nA Twisted web server supports HTTP/2 requests if you've installed the [`http2` optional dependency set](https://twistedmatrix.com/documents/19.2.0/installation/howto/optional.html).\n\n### Workarounds\nThere are no workarounds.\n\n### References\nhttps://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-002.md\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in [Twisted's Trac](https://twistedmatrix.com/trac/)\n","published":"2022-03-14T22:45:11Z","modified":"2025-02-18T05:40:23.769200Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"twisted","fixedVersion":"19.10.0"}],"fix":{"url":"https://github.com/twisted/twisted/commit/a40ab1ce5210f231abe7a448a54d7e88e48f2d5d","label":"twisted/twisted@a40ab1c"},"references":[{"type":"WEB","url":"https://github.com/twisted/twisted/security/advisories/GHSA-32gv-6cf3-wcmq"},{"type":"WEB","url":"https://github.com/twisted/twisted/commit/a40ab1ce5210f231abe7a448a54d7e88e48f2d5d"},{"type":"PACKAGE","url":"https://github.com/twisted/twisted"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2025-02-18T05:40:23.769200Z"}}