CVE-2025-9784
Undertow: undertow madeyoureset http/2 ddos vulnerability
Severity Score
7.5
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
Attend
*SSVC
Descriptions
A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive server workload by repeatedly causing server-side stream aborts. While not a protocol bug, this highlights a common implementation weakness that can be exploited to cause a denial of service (DoS).
Red Hat build of Apache Camel 4.14.2 for Spring Boot patch release and security update is now available.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:Attend
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2025-09-01 CVE Reserved
- 2025-09-02 CVE Published
- 2026-05-06 CVE Updated
- 2026-05-08 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-404: Improper Resource Shutdown or Release
- CWE-770: Allocation of Resources Without Limits or Throttling
CAPEC
References (17)
| URL | Date | SRC |
|---|
| URL | Date | SRC |
|---|
| URL | Date | SRC |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2025-9784 | 2025-09-24 | |
| https://access.redhat.com/errata/RHSA-2025:23143 | 2026-05-06 | |
| https://access.redhat.com/errata/RHSA-2026:0383 | 2026-05-06 | |
| https://access.redhat.com/errata/RHSA-2026:0384 | 2026-05-06 | |
| https://access.redhat.com/errata/RHSA-2026:0386 | 2026-05-06 | |
| https://access.redhat.com/errata/RHSA-2026:3889 | 2026-05-06 | |
| https://access.redhat.com/errata/RHSA-2026:3891 | 2026-05-06 | |
| https://access.redhat.com/errata/RHSA-2026:3892 | 2026-05-06 | |
| https://access.redhat.com/errata/RHSA-2026:4915 | 2026-05-06 | |
| https://access.redhat.com/errata/RHSA-2026:4916 | 2026-05-06 | |
| https://access.redhat.com/errata/RHSA-2026:4917 | 2026-05-06 | |
| https://access.redhat.com/errata/RHSA-2026:4924 | 2026-05-06 |
Affected Vendors, Products, and Versions
| Vendor | Product | Version | Other | Status | ||||||
|---|---|---|---|---|---|---|---|---|---|---|
| Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
| Redhat Search vendor "Redhat" | Build Of Apache Camel For Spring Boot Search vendor "Redhat" for product "Build Of Apache Camel For Spring Boot" | - | - |
Affected
| ||||||
| Redhat Search vendor "Redhat" | Fuse Search vendor "Redhat" for product "Fuse" | 7.0.0 Search vendor "Redhat" for product "Fuse" and version "7.0.0" | - |
Affected
| ||||||
| Redhat Search vendor "Redhat" | Jboss Enterprise Application Platform Search vendor "Redhat" for product "Jboss Enterprise Application Platform" | 7.0.0 Search vendor "Redhat" for product "Jboss Enterprise Application Platform" and version "7.0.0" | - |
Affected
| ||||||
| Redhat Search vendor "Redhat" | Jboss Enterprise Application Platform Search vendor "Redhat" for product "Jboss Enterprise Application Platform" | 8.0.0 Search vendor "Redhat" for product "Jboss Enterprise Application Platform" and version "8.0.0" | - |
Affected
| ||||||
| Redhat Search vendor "Redhat" | Jboss Enterprise Application Platform Expansion Pack Search vendor "Redhat" for product "Jboss Enterprise Application Platform Expansion Pack" | - | - |
Affected
| ||||||
| Redhat Search vendor "Redhat" | Process Automation Search vendor "Redhat" for product "Process Automation" | 7.0 Search vendor "Redhat" for product "Process Automation" and version "7.0" | - |
Affected
| ||||||
| Redhat Search vendor "Redhat" | Single Sign-on Search vendor "Redhat" for product "Single Sign-on" | 7.0 Search vendor "Redhat" for product "Single Sign-on" and version "7.0" | - |
Affected
| ||||||
| Redhat Search vendor "Redhat" | Undertow Search vendor "Redhat" for product "Undertow" | - | - |
Affected
| ||||||
| Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 8.0 Search vendor "Redhat" for product "Enterprise Linux" and version "8.0" | - |
Affected
| ||||||
| Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 9.0 Search vendor "Redhat" for product "Enterprise Linux" and version "9.0" | - |
Affected
| ||||||
