Three bugs leading to excessive memory consumption have been fixed in nginx.
Three issues (CVE-2019-9511, CVE-2019-9513, CVE-2019-9516) have been identified in the Nginx web server, which resulted in excessive memory consumption when using the ngx_http_v2_module and implemented from the HTTP/2 protocol. Affected versions range from 1.9.5 to 1.17.2. Fixes have been made in Nginx 1.16.1 (stable branch) and 1.17.3 (main branch). The issues were discovered by Jonathan Looney from Netflix. The 1.17.3 release included two additional fixes: […]
