Back

HIGH

Undertow: undertow madeyoureset http/2 ddos vulnerability

Published Sep 2, 2025

Description

A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive server workload by repeatedly causing server-side stream aborts. While not a protocol bug, this highlights a common implementation weakness that can be exploited to cause a denial of service (DoS).

Affected products

Remediation

Vendor solution

No mitigation is currently available that meets Red Hat Product Security’s standards for usability, deployment, applicability, or stability.

Red Hat statement

This vulnerability is rated with an Important severity. It is simple to exploit because it does not require authentication and could result in a Denial of Service (DoS). While some DoS flaws are classified as Moderate, “MadeYouReset” is Important because of the limited barriers (no specialized tooling or advanced scripting) to exploitation, which directly impacts service availability. The vulnerability arises from an implementation weakness in HTTP/2 stream reset handling — malformed client requests can trigger server-side resets without incrementing abuse counters, allowing an attacker to bypass built-in request throttling and overhead limits. Since these resets consume CPU and memory resources and can be generated at scale over a single TCP/TLS connection, a remote attacker could exhaust server capacity quickly, impacting all legitimate clients.

Red Hat mitigation

No mitigation is currently available that meets Red Hat Product Security’s standards for usability, deployment, applicability, or stability.

Metrics

References (27)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Sep 2, 2025
Updated Sep 4, 2026
Reserved Sep 1, 2025
CISA Vulnrichment
Updated Sep 2, 2025
NVD
Status Modified
Modified Sep 4, 2026
Red Hat
Severity Important
Public date Sep 1, 2025
GHSA-95H4-W6J8-2RP8