CVE-2025-9784
A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive server workload by repeatedly causing server-side stream aborts. While not a protocol bug, this highlights a common implementation weakness that can be exploited to cause a denial of service (DoS).
Scoring
- Severity
- HIGH
- CVSS base score
- 7.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS probability
- 2.33%
- CWE
- CWE-770
- Published
- 2025-09-02
- Last modified
- 2026-09-04
Affected products
- Red Hat Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
- Red Hat Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
- Red Hat Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
- Red Hat Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
- Red Hat Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
- Red Hat Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
- Red Hat Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
- Red Hat Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
Weakness type
Related vulnerabilities
- CVE-2026-1168 — Allocation of Resources Without Limits or Throttling in GitLab
- CVE-2025-14871 — Allocation of Resources Without Limits or Throttling in GitLab
- CVE-2026-88878 — Traefik v2.8.2 through v3.6 HTTP/3 Timeout Bypass
- CVE-2026-82439 — Apache Storm DRPC: Unauthenticated Unbounded Memory Growth in DRPC
- CVE-2026-72684 — Allocation of Resources Without Limits or Throttling in Elasticsearch Leading to Denial of Service
- CVE-2026-74878 — openssl_encrypt before 1.4.0 TOTP Rate Limiter Bypass
- CVE-2026-77337 — CakePHP: Potential Authentication bypass with CookieAuthenticator
- CVE-2026-79921 — amqp091-go has a Potential Memory Exhaustion/Protocol Violation via Broker-Controlled Oversized Payload