Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2019-9511_Priority-Churn-Data-Dribble — Lightweight HTTP/2 probes for controlled validation of CVE-2019-9511 (Data Dribble) and CVE-2019-9513 (Priority Churn) DoS vectors in authorized environments. | Kitploit
Tools/GitHubGitHub/harley-ghostie/cve-2019-9511_priority-churn-data-dribble
Vulnerability AnalysisExploitationWeb SecurityNetwork SecurityPenetration Testing
GitHubharley-ghostie/cve-2019-9511_priority-churn-data-dribble

CVE-2019-9511_Priority-Churn-Data-Dribble

Lightweight HTTP/2 probes for controlled validation of CVE-2019-9511 (Data Dribble) and CVE-2019-9513 (Priority Churn) DoS vectors in authorized environments.

View Repository
55 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

HTTP/2 CVE-2019-9511 & CVE-2019-9513 Lightweight Probes

Repository with controlled validation scripts for behaviors associated with CVEs CVE-2019-9511 and CVE-2019-9513, both related to denial of service vectors in HTTP/2 implementations.

The scripts were created to support technical validations in authorized environments, allowing observation of whether the server negotiates HTTP/2 and responds to specific patterns related to Data Dribble and Priority Churn, without executing a denial of service attack.

The proposal is to demonstrate the vector in a light and safe manner, with low request volume and without the intention of making the environment unavailable.


CVEs covered

CVENameScriptDescription
CVE-2019-9511HTTP/2 Data Dribbledata_dribble_probe.pyValidates HTTP/2 flow control behavior by releasing small volumes of data in a controlled manner.
CVE-2019-9513HTTP/2 Priority Churn / Resource Looppriority_churn_probe.pyValidates processing behavior of PRIORITY frames at low intensity.

Vulnerability summary

CVE-2019-9511 — HTTP/2 Data Dribble

CVE-2019-9511, known as HTTP/2 Data Dribble, affects some HTTP/2 implementations that do not efficiently handle flow window manipulation and gradual data delivery.

In this scenario, an attacker can request data from the server and manipulate flow control to keep the response open and deliver it in small blocks, such as 1-byte packets. Depending on the implementation, this behavior can cause excessive CPU, memory, or connection resource consumption, resulting in a denial of service risk.

In this repository, the related script is:

data_dribble_probe.py

The script's objective is to validate the behavior lightly, without generating aggressive load and without attempting to cause unavailability.

References:

  • https://nvd.nist.gov/vuln/detail/CVE-2019-9511
  • https://www.cve.org/CVERecord?id=CVE-2019-9511
  • https://ubuntu.com/security/CVE-2019-9511

CVE-2019-9513 — HTTP/2 Priority Churn / Resource Loop

CVE-2019-9513, known as HTTP/2 Priority Churn or Resource Loop, affects some HTTP/2 implementations that process continuous changes to the stream priority tree in a costly manner.

In this scenario, an attacker can create multiple streams and repeatedly change the priority between them, causing churn in the priority tree. Depending on the implementation, this behavior can cause excessive CPU consumption and lead to denial of service.

In this repository, the related script is:

priority_churn_probe.py

The script's objective is to validate whether the server accepts and processes PRIORITY frames, using low intensity and without executing a DoS attack.

References:

  • https://nvd.nist.gov/vuln/detail/CVE-2019-9513
  • https://www.cve.org/CVERecord?id=CVE-2019-9513
  • https://ubuntu.com/security/CVE-2019-9513

Note on affected versions

The CVEs CVE-2019-9511 and CVE-2019-9513 are not associated with a single specific version of a web server, such as only nginx, Apache, or Tomcat.

They affect certain HTTP/2 implementations in different products, libraries, proxies, load balancers, and servers. Therefore, validation should consider which component is negotiating and processing HTTP/2 in the analyzed environment.

Examples of components that may be involved:

nginx
Apache HTTP Server
Envoy
HAProxy
Tomcat
Jetty
Node.js
Go net/http2
nghttp2
CDN
WAF
Load Balancer
Ingress Controller Kubernetes

The first technical criterion is to confirm whether the service negotiates HTTP/2 via ALPN. If the service does not negotiate h2, these scripts are not applicable.

Confirmation of vulnerability by version should be based on the manufacturer's official advisory for the identified component.


Pre-validation: check HTTP/2 support

Before running the scripts, validate whether the target negotiates HTTP/2 via ALPN.

Use only the domain in the command, without https://.

openssl s_client -alpn h2 -connect exemplo.com.br:443 </dev/null 2>/dev/null | grep -i "ALPN"

You can also use a placeholder:

openssl s_client -alpn h2 -connect <HOST>:443 </dev/null 2>/dev/null | grep -i "ALPN"

Expected output:

ALPN protocol: h2

If the output indicates h2, the service negotiates HTTP/2 and the scripts may be applicable.

If there is no return or the negotiated protocol is another, such as http/1.1, the scripts are not applicable for that endpoint.

Script overview

ScriptRelated CVEObjectiveWhen to use
data_dribble_probe.pyCVE-2019-9511Validate behavior associated with Data Dribble using window control to release small data blocksUse when the server supports HTTP/2 and there is a need to verify DATA frame delivery behavior with a reduced window.
priority_churn_probe.pyCVE-2019-9513Validate behavior associated with Priority Churn using PRIORITY frames at low intensityUse when the server supports HTTP/2 and there is a need to verify if it processes stream priority changes.

Recommended usage flow

The most logical order for using the scripts is:

1. HTTP/2 pre-validation with openssl
   ↓
2. priority_churn_probe.py
   ↓
3. data_dribble_probe.py

Quick explanation of the flow

First, use the command with openssl to confirm whether the target negotiates HTTP/2. Then use priority_churn_probe.py to validate whether the server accepts and processes priority frames. Next, use data_dribble_probe.py to observe the server's behavior when faced with a reduced flow window, releasing small volumes of data in a controlled manner.

Both scripts are lightweight probes. They are not intended to cause unavailability, but rather to generate technical evidence of the observed behavior.


Scripts

priority_churn_probe.py

Description

priority_churn_probe.py is a lightweight PoC for behavioral validation related to CVE-2019-9513, known as HTTP/2 Priority Churn.

The script establishes an HTTP/2 connection via TLS, opens small HTTP streams, and sends priority changes via PRIORITY frames. Then it measures latency before and after sending these frames to observe any variation in processing.

What the script does

  • Negotiates HTTP/2 via ALPN;
  • Opens a TLS connection to the provided host;
  • Sends simple GET requests to up to three paths;
  • Measures initial latency using PING;
  • Uses fallback with GET if PING is not sufficient;
  • Sends PRIORITY frames at low intensity;
  • Measures latency after the priority churn;
  • Displays a comparison between the time before and after the test.

Usage scenario

Use this script when it is necessary to validate whether an HTTP/2 server accepts and processes priority frames related to the Priority Churn vector, without performing an aggressive DoS test.

It is appropriate for controlled validation in pentests, HTTP/2 exposure analysis, and technical proof of vulnerable or potentially sensitive behavior.

Fields/parameters that must be changed

The script receives values via command line arguments:

--host
--port
--paths
--shuffles

Explanation of parameters

ParameterDescription
--hostFQDN of the authorized target. Do not include https://.
--portTLS port where the HTTP/2 service is available. Default: 443.
--pathsList of simple paths to open HTTP/2 streams.
--shufflesNumber of priority change cycles. Keep low for safe testing.

Ideal path for testing

Use light, public, low-impact paths, such as:

/
/robots.txt
/favicon.ico
/health
/login

Avoid paths that execute heavy operations, complex queries, report generation, upload, advanced search, or any functionality that generates load on the backend.

Example of safe use

Download Tool