Undertow: undertow madeyoureset http/2 ddos vulnerability
Published Sep 2, 2025
7.5
HIGHCVSS 3.1
EPSS 2.33%
Description
A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive server workload by repeatedly causing server-side stream aborts. While not a protocol bug, this highlights a common implementation weakness that can be exploited to cause a denial of service (DoS).
Affected products
-
-
-
- Vendor Red Hat Product Red Hat JBoss Enterprise Application Platform Expansion Pack Defaultaffected
-
-
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||
|---|---|---|---|---|---|---|
| Red Hat | Red Hat Data Grid 8 | affected |
| |||
| Red Hat | Red Hat Fuse 7 | affected |
| |||
| Red Hat | Red Hat JBoss Enterprise Application Platform 7 | affected |
| |||
| Red Hat | Red Hat JBoss Enterprise Application Platform Expansion Pack | affected |
| |||
| Red Hat | Red Hat Process Automation 7 | affected |
| |||
| Red Hat | Red Hat Single Sign-On 7 | affected |
|
- n/a
- 7.0.0
- 7.0.0
- 8.0.0
- n/a
- 7.0
- 7.0
- n/a
- 8.0
- 9.0
No data.
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7
eap7-undertow-0:1.4.18-21.SP19_redhat_00001.1.ep7.el7
Fixed · RHSA-2026:33372
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7
eap7-undertow-0:2.0.41-8.SP9_redhat_00001.1.el7eap
Fixed · RHSA-2026:33371
Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7
eap7-undertow-0:2.2.39-1.Final_redhat_00001.1.el7eap
Fixed · RHSA-2026:4915
Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7
eap7-wildfly-0:7.4.24-4.GA_redhat_00002.1.el7eap
Fixed · RHSA-2026:4915
Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 8
eap7-undertow-0:2.2.39-1.Final_redhat_00001.1.el8eap
Fixed · RHSA-2026:4916
Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 8
eap7-wildfly-0:7.4.24-4.GA_redhat_00002.1.el8eap
Fixed · RHSA-2026:4916
Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 9
eap7-undertow-0:2.2.39-1.Final_redhat_00001.1.el9eap
Fixed · RHSA-2026:4917
Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 9
eap7-wildfly-0:7.4.24-4.GA_redhat_00002.1.el9eap
Fixed · RHSA-2026:4917
Red Hat JBoss Enterprise Application Platform 7.4.24
io.undertow/undertow-core:2.2.39.Final-redhat-00001
Fixed · RHSA-2026:4924
Red Hat JBoss Enterprise Application Platform 8.0
undertow-core
Fixed · RHSA-2026:3892
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
eap8-bouncycastle-0:1.83.0-1.redhat_00001.1.el8eap
Fixed · RHSA-2026:3889
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
eap8-guava-libraries-0:33.0.0-2.jre_redhat_00003.1.el8eap
Fixed · RHSA-2026:3889
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
eap8-jaxb-0:4.0.6-1.redhat_00001.1.el8eap
Fixed · RHSA-2026:3889
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
eap8-jcip-annotations-0:1.0.0-3.redhat_00009.1.el8eap
Fixed · RHSA-2026:3889
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
eap8-slf4j-jboss-logmanager-0:2.0.2-1.Final_redhat_00001.1.el8eap
Fixed · RHSA-2026:3889
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
eap8-undertow-0:2.3.23-1.SP3_redhat_00001.1.el8eap
Fixed · RHSA-2026:3889
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
eap8-bouncycastle-0:1.83.0-1.redhat_00001.1.el9eap
Fixed · RHSA-2026:3891
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
eap8-guava-libraries-0:33.0.0-2.jre_redhat_00003.1.el9eap
Fixed · RHSA-2026:3891
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
eap8-jaxb-0:4.0.6-1.redhat_00001.1.el9eap
Fixed · RHSA-2026:3891
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
eap8-jcip-annotations-0:1.0.0-3.redhat_00009.1.el9eap
Fixed · RHSA-2026:3891
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
eap8-slf4j-jboss-logmanager-0:2.0.2-1.Final_redhat_00001.1.el9eap
Fixed · RHSA-2026:3891
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
eap8-undertow-0:2.3.23-1.SP3_redhat_00001.1.el9eap
Fixed · RHSA-2026:3891
Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8
eap8-apache-cxf-0:4.0.10-1.redhat_00001.1.el8eap
Fixed · RHSA-2026:0383
Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8
eap8-bouncycastle-0:1.82.0-1.redhat_00001.1.el8eap
Fixed · RHSA-2026:0383
Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8
eap8-eap-product-conf-parent-0:801.3.0-1.GA_redhat_00001.1.el8eap
Fixed · RHSA-2026:0383
Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8
eap8-eventstream-0:1.0.1-3.redhat_00003.1.el8eap
Fixed · RHSA-2026:0383
Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8
eap8-hibernate-0:6.6.36-1.Final_redhat_00001.1.el8eap
Fixed · RHSA-2026:0383
Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8
eap8-jboss-el-api_5.0_spec-0:4.0.2-1.Final_redhat_00001.1.el8eap
Fixed · RHSA-2026:0383
Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8
eap8-jboss-threads-0:2.5.0-1.redhat_00001.1.el8eap
Fixed · RHSA-2026:0383
Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8
eap8-undertow-0:2.3.20-2.SP4_redhat_00001.1.el8eap
Fixed · RHSA-2026:0383
Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8
eap8-wildfly-0:8.1.3-4.GA_redhat_00006.1.el8eap
Fixed · RHSA-2026:0383
Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8
eap8-wildfly-clustering-0:5.0.12-1.Final_redhat_00001.1.el8eap
Fixed · RHSA-2026:0383
Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8
eap8-wildfly-elytron-0:2.6.6-1.Final_redhat_00001.1.el8eap
Fixed · RHSA-2026:0383
Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8
eap8-wildfly-javadocs-0:8.1.1-4.GA_redhat_00007.1.el8eap
Fixed · RHSA-2026:0383
Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9
eap8-apache-cxf-0:4.0.10-1.redhat_00001.1.el9eap
Fixed · RHSA-2026:0384
Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9
eap8-bouncycastle-0:1.82.0-1.redhat_00001.1.el9eap
Fixed · RHSA-2026:0384
Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9
eap8-eap-product-conf-parent-0:801.3.0-1.GA_redhat_00001.1.el9eap
Fixed · RHSA-2026:0384
Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9
eap8-eventstream-0:1.0.1-3.redhat_00003.1.el9eap
Fixed · RHSA-2026:0384
Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9
eap8-hibernate-0:6.6.36-1.Final_redhat_00001.1.el9eap
Fixed · RHSA-2026:0384
Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9
eap8-jboss-el-api_5.0_spec-0:4.0.2-1.Final_redhat_00001.1.el9eap
Fixed · RHSA-2026:0384
Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9
eap8-jboss-threads-0:2.5.0-1.redhat_00001.1.el9eap
Fixed · RHSA-2026:0384
Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9
eap8-undertow-0:2.3.20-2.SP4_redhat_00001.1.el9eap
Fixed · RHSA-2026:0384
Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9
eap8-wildfly-0:8.1.3-4.GA_redhat_00006.1.el9eap
Fixed · RHSA-2026:0384
Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9
eap8-wildfly-clustering-0:5.0.12-1.Final_redhat_00001.1.el9eap
Fixed · RHSA-2026:0384
Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9
eap8-wildfly-elytron-0:2.6.6-1.Final_redhat_00001.1.el9eap
Fixed · RHSA-2026:0384
Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9
eap8-wildfly-javadocs-0:8.1.1-4.GA_redhat_00007.1.el9eap
Fixed · RHSA-2026:0384
Red Hat JBoss Enterprise Application Platform 8.1.6
io.undertow/undertow-core:2.3.24.SP2-redhat-00001
Fixed · RHSA-2026:0386
Red Hat build of Apache Camel 4.14.2 for Spring Boot 3.5.8
undertow-core
Fixed · RHSA-2025:23143
Red Hat Data Grid 8
undertow-core
Will not fix
Red Hat Enterprise Linux 10
moditect
Not affected
Red Hat Enterprise Linux 8
pki-core:10.6/resteasy
Not affected
Red Hat Enterprise Linux 8
pki-deps:10.6/resteasy
Not affected
Red Hat Enterprise Linux 9
resteasy
Not affected
Red Hat Fuse 7
undertow-core
Will not fix
Red Hat JBoss Enterprise Application Platform 7
undertow-core
Affected
Red Hat JBoss Enterprise Application Platform 8
org.jberet-jberet-parent
Not affected
Red Hat JBoss Enterprise Application Platform 8
org.jboss.eap-jboss-eap-xp
Not affected
Red Hat JBoss Enterprise Application Platform Expansion Pack
org.jboss.eap-jboss-eap-xp
Affected
Red Hat JBoss Enterprise Application Platform Expansion Pack
undertow-core
Not affected
Red Hat Process Automation 7
undertow-core
Will not fix
Red Hat Single Sign-On 7
undertow-core
Will not fix
Red Hat build of Apache Camel - HawtIO 4
undertow-core
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 | eap7-undertow-0:1.4.18-21.SP19_redhat_00001.1.ep7.el7 | Fixed | RHSA-2026:33372 |
| Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 | eap7-undertow-0:2.0.41-8.SP9_redhat_00001.1.el7eap | Fixed | RHSA-2026:33371 |
| Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7 | eap7-undertow-0:2.2.39-1.Final_redhat_00001.1.el7eap | Fixed | RHSA-2026:4915 |
| Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7 | eap7-wildfly-0:7.4.24-4.GA_redhat_00002.1.el7eap | Fixed | RHSA-2026:4915 |
| Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 8 | eap7-undertow-0:2.2.39-1.Final_redhat_00001.1.el8eap | Fixed | RHSA-2026:4916 |
| Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 8 | eap7-wildfly-0:7.4.24-4.GA_redhat_00002.1.el8eap | Fixed | RHSA-2026:4916 |
| Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 9 | eap7-undertow-0:2.2.39-1.Final_redhat_00001.1.el9eap | Fixed | RHSA-2026:4917 |
| Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 9 | eap7-wildfly-0:7.4.24-4.GA_redhat_00002.1.el9eap | Fixed | RHSA-2026:4917 |
| Red Hat JBoss Enterprise Application Platform 7.4.24 | io.undertow/undertow-core:2.2.39.Final-redhat-00001 | Fixed | RHSA-2026:4924 |
| Red Hat JBoss Enterprise Application Platform 8.0 | undertow-core | Fixed | RHSA-2026:3892 |
| Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 | eap8-bouncycastle-0:1.83.0-1.redhat_00001.1.el8eap | Fixed | RHSA-2026:3889 |
| Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 | eap8-guava-libraries-0:33.0.0-2.jre_redhat_00003.1.el8eap | Fixed | RHSA-2026:3889 |
| Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 | eap8-jaxb-0:4.0.6-1.redhat_00001.1.el8eap | Fixed | RHSA-2026:3889 |
| Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 | eap8-jcip-annotations-0:1.0.0-3.redhat_00009.1.el8eap | Fixed | RHSA-2026:3889 |
| Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 | eap8-slf4j-jboss-logmanager-0:2.0.2-1.Final_redhat_00001.1.el8eap | Fixed | RHSA-2026:3889 |
| Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 | eap8-undertow-0:2.3.23-1.SP3_redhat_00001.1.el8eap | Fixed | RHSA-2026:3889 |
| Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | eap8-bouncycastle-0:1.83.0-1.redhat_00001.1.el9eap | Fixed | RHSA-2026:3891 |
| Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | eap8-guava-libraries-0:33.0.0-2.jre_redhat_00003.1.el9eap | Fixed | RHSA-2026:3891 |
| Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | eap8-jaxb-0:4.0.6-1.redhat_00001.1.el9eap | Fixed | RHSA-2026:3891 |
| Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | eap8-jcip-annotations-0:1.0.0-3.redhat_00009.1.el9eap | Fixed | RHSA-2026:3891 |
| Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | eap8-slf4j-jboss-logmanager-0:2.0.2-1.Final_redhat_00001.1.el9eap | Fixed | RHSA-2026:3891 |
| Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | eap8-undertow-0:2.3.23-1.SP3_redhat_00001.1.el9eap | Fixed | RHSA-2026:3891 |
| Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8 | eap8-apache-cxf-0:4.0.10-1.redhat_00001.1.el8eap | Fixed | RHSA-2026:0383 |
| Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8 | eap8-bouncycastle-0:1.82.0-1.redhat_00001.1.el8eap | Fixed | RHSA-2026:0383 |
| Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8 | eap8-eap-product-conf-parent-0:801.3.0-1.GA_redhat_00001.1.el8eap | Fixed | RHSA-2026:0383 |
| Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8 | eap8-eventstream-0:1.0.1-3.redhat_00003.1.el8eap | Fixed | RHSA-2026:0383 |
| Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8 | eap8-hibernate-0:6.6.36-1.Final_redhat_00001.1.el8eap | Fixed | RHSA-2026:0383 |
| Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8 | eap8-jboss-el-api_5.0_spec-0:4.0.2-1.Final_redhat_00001.1.el8eap | Fixed | RHSA-2026:0383 |
| Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8 | eap8-jboss-threads-0:2.5.0-1.redhat_00001.1.el8eap | Fixed | RHSA-2026:0383 |
| Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8 | eap8-undertow-0:2.3.20-2.SP4_redhat_00001.1.el8eap | Fixed | RHSA-2026:0383 |
| Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8 | eap8-wildfly-0:8.1.3-4.GA_redhat_00006.1.el8eap | Fixed | RHSA-2026:0383 |
| Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8 | eap8-wildfly-clustering-0:5.0.12-1.Final_redhat_00001.1.el8eap | Fixed | RHSA-2026:0383 |
| Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8 | eap8-wildfly-elytron-0:2.6.6-1.Final_redhat_00001.1.el8eap | Fixed | RHSA-2026:0383 |
| Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8 | eap8-wildfly-javadocs-0:8.1.1-4.GA_redhat_00007.1.el8eap | Fixed | RHSA-2026:0383 |
| Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9 | eap8-apache-cxf-0:4.0.10-1.redhat_00001.1.el9eap | Fixed | RHSA-2026:0384 |
| Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9 | eap8-bouncycastle-0:1.82.0-1.redhat_00001.1.el9eap | Fixed | RHSA-2026:0384 |
| Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9 | eap8-eap-product-conf-parent-0:801.3.0-1.GA_redhat_00001.1.el9eap | Fixed | RHSA-2026:0384 |
| Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9 | eap8-eventstream-0:1.0.1-3.redhat_00003.1.el9eap | Fixed | RHSA-2026:0384 |
| Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9 | eap8-hibernate-0:6.6.36-1.Final_redhat_00001.1.el9eap | Fixed | RHSA-2026:0384 |
| Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9 | eap8-jboss-el-api_5.0_spec-0:4.0.2-1.Final_redhat_00001.1.el9eap | Fixed | RHSA-2026:0384 |
| Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9 | eap8-jboss-threads-0:2.5.0-1.redhat_00001.1.el9eap | Fixed | RHSA-2026:0384 |
| Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9 | eap8-undertow-0:2.3.20-2.SP4_redhat_00001.1.el9eap | Fixed | RHSA-2026:0384 |
| Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9 | eap8-wildfly-0:8.1.3-4.GA_redhat_00006.1.el9eap | Fixed | RHSA-2026:0384 |
| Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9 | eap8-wildfly-clustering-0:5.0.12-1.Final_redhat_00001.1.el9eap | Fixed | RHSA-2026:0384 |
| Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9 | eap8-wildfly-elytron-0:2.6.6-1.Final_redhat_00001.1.el9eap | Fixed | RHSA-2026:0384 |
| Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9 | eap8-wildfly-javadocs-0:8.1.1-4.GA_redhat_00007.1.el9eap | Fixed | RHSA-2026:0384 |
| Red Hat JBoss Enterprise Application Platform 8.1.6 | io.undertow/undertow-core:2.3.24.SP2-redhat-00001 | Fixed | RHSA-2026:0386 |
| Red Hat build of Apache Camel 4.14.2 for Spring Boot 3.5.8 | undertow-core | Fixed | RHSA-2025:23143 |
| Red Hat Data Grid 8 | undertow-core | Will not fix | n/a |
| Red Hat Enterprise Linux 10 | moditect | Not affected | n/a |
| Red Hat Enterprise Linux 8 | pki-core:10.6/resteasy | Not affected | n/a |
| Red Hat Enterprise Linux 8 | pki-deps:10.6/resteasy | Not affected | n/a |
| Red Hat Enterprise Linux 9 | resteasy | Not affected | n/a |
| Red Hat Fuse 7 | undertow-core | Will not fix | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | undertow-core | Affected | n/a |
| Red Hat JBoss Enterprise Application Platform 8 | org.jberet-jberet-parent | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 8 | org.jboss.eap-jboss-eap-xp | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | org.jboss.eap-jboss-eap-xp | Affected | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | undertow-core | Not affected | n/a |
| Red Hat Process Automation 7 | undertow-core | Will not fix | n/a |
| Red Hat Single Sign-On 7 | undertow-core | Will not fix | n/a |
| Red Hat build of Apache Camel - HawtIO 4 | undertow-core | Not affected | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
No mitigation is currently available that meets Red Hat Product Security’s standards for usability, deployment, applicability, or stability.
Red Hat statement
This vulnerability is rated with an Important severity. It is simple to exploit because it does not require authentication and could result in a Denial of Service (DoS). While some DoS flaws are classified as Moderate, “MadeYouReset” is Important because of the limited barriers (no specialized tooling or advanced scripting) to exploitation, which directly impacts service availability. The vulnerability arises from an implementation weakness in HTTP/2 stream reset handling — malformed client requests can trigger server-side resets without incrementing abuse counters, allowing an attacker to bypass built-in request throttling and overhead limits. Since these resets consume CPU and memory resources and can be generated at scale over a single TCP/TLS connection, a remote attacker could exhaust server capacity quickly, impacting all legitimate clients.
Red Hat mitigation
No mitigation is currently available that meets Red Hat Product Security’s standards for usability, deployment, applicability, or stability.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
YesTechnical Impact
PartialDecision
n/aAssessed Sep 2, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2025–2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (6 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 2.33% (0.02325) | 82.88th | v5 (v2026.06.15) |
| Jun 15, 2026 | 2.17% (0.02170) | 79.86th | v5 (v2026.06.15) |
| May 8, 2026 | 1.70% (0.01700) | 82.41th | v4 (v2025.03.14) |
| Jan 15, 2026 | 0.61% (0.00606) | 69.04th | v4 (v2025.03.14) |
| Jan 9, 2026 | 2.21% (0.02215) | 84.03th | v4 (v2025.03.14) |
| Sep 3, 2025 | 0.24% (0.00243) | 47.66th | v4 (v2025.03.14) |
References (27)
- https://access.redhat.com/errata/RHSA-2025:23143 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:0383 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:0384 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:0386 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:33371 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:33372 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:3889 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:3891 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:3892 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:4915 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:4916 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:4917 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:4924 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2025-9784 vdb-entryx_refsource_REDHATVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2392306 issue-trackingx_refsource_REDHATIssue Tracking
- https://github.com/advisories/GHSA-95h4-w6j8-2rp8 Advisory
- https://github.com/undertow-io/undertow/pull/1778
- https://github.com/undertow-io/undertow/pull/1802
- https://github.com/undertow-io/undertow/pull/1803
- https://github.com/undertow-io/undertow/pull/1804
- https://github.com/undertow-io/undertow/pull/1805
- https://github.com/undertow-io/undertow/releases/tag/2.2.38.Final
- https://issues.redhat.com/browse/UNDERTOW-2598
- https://kb.cert.org/vuls/id/767506
- https://nvd.nist.gov/vuln/detail/CVE-2025-9784
- https://www.cve.org/CVERecord?id=CVE-2025-9784
- https://www.kb.cert.org/vuls/id/767506
Change history (0)
No recorded changes yet.