Description
A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive server workload by repeatedly causing server-side stream aborts. While not a protocol bug, this highlights a common implementation weakness that can be exploited to cause a denial of service (DoS).
Published: 2025-09-02
Score: 7.5 High
EPSS: 2.2% Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

A flaw was found in Undertow where malformed client requests can trigger server‑side stream resets without triggering abuse counters. The issue, called the “MadeYouReset” attack, lets malicious clients repeatedly cause stream aborts that consume significant server resources, effectively exhausting processing capacity and violating availability. This is not a protocol error but an implementation weakness that allows an attacker to force the server into a costly state without triggering normal countermeasures.

Affected Systems

The vulnerability affects Red Hat products that embed Undertow. All affected releases include Red Hat Enterprise Linux 10, 9, and 8; Red Hat JBoss Enterprise Application Platform 7.4 (including the ELS variants on RHEL 7, 8, 9); Red Hat JBoss Enterprise Application Platform 8.0, 8.1 (and their corresponding ELS variants for RHEL 8 and 9); Red Hat JBoss Enterprise Application Platform 8 (generic); Red Hat JBoss Enterprise Application Platform Expansion Pack; Red Hat Data Grid 8; Red Hat Fuse 7; Red Hat Process Automation 7; Red Hat Single Sign‑On 7; and the Red Hat build of Apache Camel – HawtIO 4 as well as the Red Hat build of Apache Camel 4.14.2 for Spring Boot 3.5.8. The flaw is present in all these releases until the 2.2.38.Final Undertow update or later.

Risk and Exploitability

The CVSS score is 7.5 and the EPSS score of 2 % indicates a moderate likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, but its high impact and network‑based attack vector (HTTP/2 client requests) make it a significant risk. An attacker can trigger the issue from any network position that can communicate with the Undertow server; no authentication or special privileges are required. The lack of abuse counters means repeated resets can be sent at line speed without detection, leading to sustained denial of service.

Generated by OpenCVE AI on April 28, 2026 at 10:51 UTC.

Remediation

Vendor Workaround

No mitigation is currently available that meets Red Hat Product Security’s standards for usability, deployment, applicability, or stability.


OpenCVE Recommended Actions

  • Apply the Red Hat security updates referenced in the errata (RHSA‑2025:23143 and the subsequent RHSA‑2026 releases) so that the Undertow library is upgraded to 2.2.38.Final or newer.
  • Deploy the patched JBoss/Red Hat Enterprise products that include the updated Undertow component; verify that the deployed Undertow version matches the patched release.
  • Apply network‑layer controls such as rate limiting or HTTP/2 stream reset filtering to reduce the effect of an unpatched or partially patched environment until a full upgrade can be performed.

Generated by OpenCVE AI on April 28, 2026 at 10:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-26388 A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive server workload by repeatedly causing server-side stream aborts. While not a protocol bug, this highlights a common implementation weakness that can be exploited to cause a denial of service (DoS).
Github GHSA Github GHSA GHSA-95h4-w6j8-2rp8 Undertow MadeYouReset HTTP/2 DDoS Vulnerability
History

Wed, 06 May 2026 15:30:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:jboss_enterprise_application_platform:7

Wed, 18 Mar 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Redhat jboss Enterprise Application Platform Els
CPEs cpe:/a:redhat:jboss_enterprise_application_platform:7 cpe:/a:redhat:jboss_enterprise_application_platform:7.4
cpe:/a:redhat:jboss_enterprise_application_platform_els:7.4::el7
cpe:/a:redhat:jboss_enterprise_application_platform_els:7.4::el8
cpe:/a:redhat:jboss_enterprise_application_platform_els:7.4::el9
Vendors & Products Redhat jboss Enterprise Application Platform Els
References

Thu, 05 Mar 2026 19:30:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:jboss_enterprise_application_platform:8.0::el9
References

Thu, 08 Jan 2026 22:45:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:jboss_enterprise_application_platform:8.1::el8
References

Thu, 08 Jan 2026 17:15:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:jboss_enterprise_application_platform:8.0::el8
cpe:/a:redhat:jboss_enterprise_application_platform:8.1::el9
References

Thu, 11 Dec 2025 22:45:00 +0000

Type Values Removed Values Added
First Time appeared Redhat apache Camel Spring Boot
CPEs cpe:/a:redhat:camel_spring_boot:4 cpe:/a:redhat:apache_camel_spring_boot:4.14
Vendors & Products Redhat camel Spring Boot
Redhat apache Camel Spring Boot
References

Mon, 08 Dec 2025 07:45:00 +0000

Type Values Removed Values Added
References

Fri, 07 Nov 2025 22:00:00 +0000

Type Values Removed Values Added
References

Mon, 03 Nov 2025 20:30:00 +0000

Type Values Removed Values Added
References

Wed, 08 Oct 2025 14:15:00 +0000

Type Values Removed Values Added
CPEs cpe:/o:redhat:rhivos:1
Vendors & Products Redhat rhivos

Thu, 02 Oct 2025 22:00:00 +0000

Type Values Removed Values Added
First Time appeared Redhat rhivos
CPEs cpe:/o:redhat:rhivos:1
Vendors & Products Redhat rhivos

Wed, 24 Sep 2025 13:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-770
References

Wed, 10 Sep 2025 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Redhat build Of Apache Camel For Spring Boot
Redhat fuse
Redhat jboss Enterprise Application Platform Expansion Pack
Redhat process Automation
Redhat single Sign-on
Redhat undertow
CPEs cpe:2.3:a:redhat:build_of_apache_camel_for_spring_boot:-:*:*:*:*:*:*:*
cpe:2.3:a:redhat:fuse:7.0.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.0.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform:8.0.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform_expansion_pack:-:*:*:*:*:*:*:*
cpe:2.3:a:redhat:process_automation:7.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:single_sign-on:7.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:undertow:-:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:-:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
Vendors & Products Redhat build Of Apache Camel For Spring Boot
Redhat fuse
Redhat jboss Enterprise Application Platform Expansion Pack
Redhat process Automation
Redhat single Sign-on
Redhat undertow

Tue, 02 Sep 2025 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400

Tue, 02 Sep 2025 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-404

Tue, 02 Sep 2025 14:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 02 Sep 2025 13:45:00 +0000

Type Values Removed Values Added
Description No description is available for this CVE. A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive server workload by repeatedly causing server-side stream aborts. While not a protocol bug, this highlights a common implementation weakness that can be exploited to cause a denial of service (DoS).
Title undertow: Undertow MadeYouReset HTTP/2 DDoS Vulnerability Undertow: undertow madeyoureset http/2 ddos vulnerability
First Time appeared Redhat
Redhat apache Camel Hawtio
Redhat camel Spring Boot
Redhat enterprise Linux
Redhat jboss Data Grid
Redhat jboss Enterprise Application Platform
Redhat jboss Enterprise Bpms Platform
Redhat jboss Fuse
Redhat jbosseapxp
Redhat red Hat Single Sign On
CPEs cpe:/a:redhat:apache_camel_hawtio:4
cpe:/a:redhat:camel_spring_boot:4
cpe:/a:redhat:jboss_data_grid:8
cpe:/a:redhat:jboss_enterprise_application_platform:7
cpe:/a:redhat:jboss_enterprise_application_platform:8
cpe:/a:redhat:jboss_enterprise_bpms_platform:7
cpe:/a:redhat:jboss_fuse:7
cpe:/a:redhat:jbosseapxp
cpe:/a:redhat:red_hat_single_sign_on:7
cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat apache Camel Hawtio
Redhat camel Spring Boot
Redhat enterprise Linux
Redhat jboss Data Grid
Redhat jboss Enterprise Application Platform
Redhat jboss Enterprise Bpms Platform
Redhat jboss Fuse
Redhat jbosseapxp
Redhat red Hat Single Sign On
References

Mon, 01 Sep 2025 12:15:00 +0000

Type Values Removed Values Added
Description No description is available for this CVE.
Title undertow: Undertow MadeYouReset HTTP/2 DDoS Vulnerability
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Important


Subscriptions

Redhat Apache Camel Hawtio Apache Camel Spring Boot Build Of Apache Camel For Spring Boot Enterprise Linux Fuse Jboss Data Grid Jboss Enterprise Application Platform Jboss Enterprise Application Platform Els Jboss Enterprise Application Platform Expansion Pack Jboss Enterprise Bpms Platform Jboss Fuse Jbosseapxp Process Automation Red Hat Single Sign On Single Sign-on Undertow
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-05-06T14:33:06.077Z

Reserved: 2025-09-01T06:33:05.239Z

Link: CVE-2025-9784

cve-icon Vulnrichment

Updated: 2025-11-03T20:07:57.869Z

cve-icon NVD

Status : Modified

Published: 2025-09-02T14:15:36.593

Modified: 2026-03-18T16:16:24.440

Link: CVE-2025-9784

cve-icon Redhat

Severity : Important

Publid Date: 2025-09-01T06:21:54Z

Links: CVE-2025-9784 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-04-28T11:00:14Z

Weaknesses