GHSA-95h4-w6j8-2rp8HighCVSS 7.5

Undertow MadeYouReset HTTP/2 DDoS Vulnerability

Published
September 2, 2025
Last Modified
June 30, 2026

🔗 CVE IDs covered (1)

📋 Description

A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive server workload by repeatedly causing server-side stream aborts. While not a protocol bug, this highlights a common implementation weakness that can be exploited to cause a denial of service (DoS).

🎯 Affected products2

  • maven/io.undertow:undertow-core:< 2.2.38.Final
  • maven/io.undertow:undertow-core:>= 2.3.0.Alpha1, < 2.3.20.Final

🔗 References (26)