Junglewise Threat Intelligence

CVE-2025-9784: Red Hat Undertow denial of service via MadeYouReset attack

CVE-2025-9784 · Severity: high · CVSS 7.5 · Published 2025-09-02

Vendors: Red Hat.

Executive brief

A vulnerability in the Undertow web server allows remote attackers to overwhelm the system by sending specially crafted HTTP/2 requests. This 'MadeYouReset' attack bypasses standard security counters, potentially leading to a total service outage or significant performance degradation. Organizations using Undertow for web services or application hosting are at risk of denial-of-service attacks.

Technical details

A resource exhaustion vulnerability exists in Undertow's HTTP/2 implementation, specifically regarding how it handles malformed client requests. An attacker can send a sequence of malformed requests that trigger server-side stream resets (RST_STREAM) without incrementing the internal abuse or flood counters. This 'MadeYouReset' attack allows a remote, unauthenticated attacker to induce excessive CPU and memory workload on the server, eventually leading to a denial-of-service (DoS) condition. The issue is rooted in improper resource shutdown and lack of throttling for these specific reset scenarios. Patches are available in versions 2.2.38.Final and 2.3.20.Final.

Affected products

  • Undertow undertow-core < 2.2.38.Final, >= 2.3.0.Alpha1, < 2.3.20.Final

Timeline

  • 2025-09-02: advisory: Initial publication of GHSA-95h4-w6j8-2rp8
  • 2025-09-02: disclosed: NVD publication date
  • 2026-06-30: other: Last updated date

References

Related threats