Skip to content

Dataset

DDoS-relevant CVEs

Vulnerabilities whose impact is availability through resource exhaustion or amplification. Status, publication date and CVSS read from each NVD record. No exploitation detail.

Rows
9
Last updated
2026-08-15
Schema version
1.0
Download
JSON·CSV

DDoS-relevant CVEs

CVEAffected product or protocolDDoS relevancePublishedNVD statusCVSS v3.1RemediationNVD record
CVE-2023-44487HTTP/2 protocol implementations, broadlyRapid Reset: rapid stream open-and-cancel consumes server request handling. The vector behind the 2023 record requests-per-second attacks.2023-10-10Analyzed7.5 HIGHPatch the server; limit concurrent and cancelled streams per connection.nvd.nist.gov/vuln/detail/CVE-2023-44487
CVE-2024-27316Apache HTTP Server (nghttp2 header buffering)HTTP/2 header handling can be driven to exhaust memory — the CONTINUATION-flood class of availability bug.2024-04-04Modified7.5 HIGHUpgrade to a fixed Apache HTTP Server release.nvd.nist.gov/vuln/detail/CVE-2024-27316
CVE-2019-9511Multiple HTTP/2 implementationsWindow-size and stream-prioritisation manipulation leading to denial of service.2019-08-13Modified7.5 HIGHVendor patches from the coordinated 2019 HTTP/2 disclosure.nvd.nist.gov/vuln/detail/CVE-2019-9511
CVE-2019-9512Multiple HTTP/2 implementationsPing flood: continuous pings force the server to queue responses.2019-08-13Modified7.5 HIGHVendor patches from the coordinated 2019 HTTP/2 disclosure.nvd.nist.gov/vuln/detail/CVE-2019-9512
CVE-2019-9513Multiple HTTP/2 implementationsResource loop through repeated stream prioritisation changes.2019-08-13Modified7.5 HIGHVendor patches from the coordinated 2019 HTTP/2 disclosure.nvd.nist.gov/vuln/detail/CVE-2019-9513
CVE-2019-9514Multiple HTTP/2 implementationsReset flood — the ancestor of the 2023 Rapid Reset class.2019-08-13Modified7.5 HIGHVendor patches from the coordinated 2019 HTTP/2 disclosure.nvd.nist.gov/vuln/detail/CVE-2019-9514
CVE-2019-9515Multiple HTTP/2 implementationsSettings flood: a stream of SETTINGS frames forces the server to respond.2019-08-13Modified7.5 HIGHVendor patches from the coordinated 2019 HTTP/2 disclosure.nvd.nist.gov/vuln/detail/CVE-2019-9515
CVE-2018-1000115Memcached 1.5.5 UDP supportNetwork amplification (CWE-406) — the exposure behind the extreme memcached amplification factors.2018-03-05Modifiednot scored in CVSS v3.1 by NVD (v2 base score 5.0)Do not expose memcached to the internet; disable UDP.nvd.nist.gov/vuln/detail/CVE-2018-1000115
CVE-2016-10229Linux kernel before 4.5 (udp.c)UDP traffic triggering an unsafe second checksum calculation — a kernel-level availability and integrity exposure on the packet path.2017-04-04Modified9.8 CRITICALRun a kernel at or beyond the fixed version.nvd.nist.gov/vuln/detail/CVE-2016-10229

Sources

  1. National Vulnerability Database (NVD) CVE API

    NIST · accessed 2026-08-15

    Each row was fetched individually from the NVD 2.0 API; status and CVSS values are as NVD recorded them on the access date.

What changed

  • 2026-08-15Initial release: nine availability-impacting CVEs, each read from its NVD record.

Reuse: Free to reuse with attribution to ddosmitigationguide.com; source citations must be preserved.