Dataset
DDoS-relevant CVEs
Vulnerabilities whose impact is availability through resource exhaustion or amplification. Status, publication date and CVSS read from each NVD record. No exploitation detail.
- Rows
- 9
- Last updated
- 2026-08-15
- Schema version
- 1.0
DDoS-relevant CVEs
| CVE | Affected product or protocol | DDoS relevance | Published | NVD status | CVSS v3.1 | Remediation | NVD record |
|---|---|---|---|---|---|---|---|
| CVE-2023-44487 | HTTP/2 protocol implementations, broadly | Rapid Reset: rapid stream open-and-cancel consumes server request handling. The vector behind the 2023 record requests-per-second attacks. | 2023-10-10 | Analyzed | 7.5 HIGH | Patch the server; limit concurrent and cancelled streams per connection. | nvd.nist.gov/vuln/detail/CVE-2023-44487 |
| CVE-2024-27316 | Apache HTTP Server (nghttp2 header buffering) | HTTP/2 header handling can be driven to exhaust memory — the CONTINUATION-flood class of availability bug. | 2024-04-04 | Modified | 7.5 HIGH | Upgrade to a fixed Apache HTTP Server release. | nvd.nist.gov/vuln/detail/CVE-2024-27316 |
| CVE-2019-9511 | Multiple HTTP/2 implementations | Window-size and stream-prioritisation manipulation leading to denial of service. | 2019-08-13 | Modified | 7.5 HIGH | Vendor patches from the coordinated 2019 HTTP/2 disclosure. | nvd.nist.gov/vuln/detail/CVE-2019-9511 |
| CVE-2019-9512 | Multiple HTTP/2 implementations | Ping flood: continuous pings force the server to queue responses. | 2019-08-13 | Modified | 7.5 HIGH | Vendor patches from the coordinated 2019 HTTP/2 disclosure. | nvd.nist.gov/vuln/detail/CVE-2019-9512 |
| CVE-2019-9513 | Multiple HTTP/2 implementations | Resource loop through repeated stream prioritisation changes. | 2019-08-13 | Modified | 7.5 HIGH | Vendor patches from the coordinated 2019 HTTP/2 disclosure. | nvd.nist.gov/vuln/detail/CVE-2019-9513 |
| CVE-2019-9514 | Multiple HTTP/2 implementations | Reset flood — the ancestor of the 2023 Rapid Reset class. | 2019-08-13 | Modified | 7.5 HIGH | Vendor patches from the coordinated 2019 HTTP/2 disclosure. | nvd.nist.gov/vuln/detail/CVE-2019-9514 |
| CVE-2019-9515 | Multiple HTTP/2 implementations | Settings flood: a stream of SETTINGS frames forces the server to respond. | 2019-08-13 | Modified | 7.5 HIGH | Vendor patches from the coordinated 2019 HTTP/2 disclosure. | nvd.nist.gov/vuln/detail/CVE-2019-9515 |
| CVE-2018-1000115 | Memcached 1.5.5 UDP support | Network amplification (CWE-406) — the exposure behind the extreme memcached amplification factors. | 2018-03-05 | Modified | not scored in CVSS v3.1 by NVD (v2 base score 5.0) | Do not expose memcached to the internet; disable UDP. | nvd.nist.gov/vuln/detail/CVE-2018-1000115 |
| CVE-2016-10229 | Linux kernel before 4.5 (udp.c) | UDP traffic triggering an unsafe second checksum calculation — a kernel-level availability and integrity exposure on the packet path. | 2017-04-04 | Modified | 9.8 CRITICAL | Run a kernel at or beyond the fixed version. | nvd.nist.gov/vuln/detail/CVE-2016-10229 |
Sources
- National Vulnerability Database (NVD) CVE API
NIST · accessed 2026-08-15
Each row was fetched individually from the NVD 2.0 API; status and CVSS values are as NVD recorded them on the access date.
What changed
- 2026-08-15Initial release: nine availability-impacting CVEs, each read from its NVD record.
Reuse: Free to reuse with attribution to ddosmitigationguide.com; source citations must be preserved.