{"id":"CVE-2025-9784","aliases":["GHSA-95h4-w6j8-2rp8"],"url":"https://o3.security/vulnerability/CVE-2025-9784","summary":"Undertow: undertow madeyoureset http/2 ddos vulnerability","details":"A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the \"MadeYouReset\" attack, allows malicious clients to induce excessive server workload by repeatedly causing server-side stream aborts. While not a protocol bug, this highlights a common implementation weakness that can be exploited to cause a denial of service (DoS).","published":"2025-09-02T13:37:59.772Z","modified":"2026-08-05T03:30:24.622532682Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"io.undertow:undertow-core","fixedVersion":"2.2.38.Final"},{"ecosystem":"Maven","name":"io.undertow:undertow-core","fixedVersion":"2.3.20.Final"}],"fix":{"url":"https://github.com/undertow-io/undertow/pull/1778","label":"undertow-io/undertow#1778"},"references":[{"type":"WEB","url":"https://access.redhat.com/downloads/content/package-browser/"},{"type":"WEB","url":"https://access.redhat.com/jbossnetwork/restricted/listSoftware.html"},{"type":"WEB","url":"https://github.com/undertow-io/undertow/"},{"type":"WEB","url":"https://github.com/undertow-io/undertow/releases/tag/2.2.38.Final"},{"type":"WEB","url":"https://issues.redhat.com/browse/UNDERTOW-2598"},{"type":"WEB","url":"https://kb.cert.org/vuls/id/767506"},{"type":"WEB","url":"https://www.kb.cert.org/vuls/id/767506"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2025:23143"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:0383"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:0384"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:0386"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:33371"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:33372"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:3889"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:3891"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:3892"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:4915"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:4916"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:4917"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:4924"},{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2025-9784"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/9xxx/CVE-2025-9784.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-9784"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2392306"},{"type":"FIX","url":"https://github.com/undertow-io/undertow/pull/1778"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-05T03:30:24.622532682Z"}}