Description
A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive server workload by repeatedly causing server-side stream aborts. While not a protocol bug, this highlights a common implementation weakness that can be exploited to cause a denial of service (DoS).
Problem types
Allocation of Resources Without Limits or Throttling
Product status
Any version before 2.2.38.Final
2.2.39.Final-redhat-00001 (rpm) before *
0:2.2.39-1.Final_redhat_00001.1.el7eap (rpm) before *
0:7.4.24-4.GA_redhat_00002.1.el7eap (rpm) before *
0:2.2.39-1.Final_redhat_00001.1.el8eap (rpm) before *
0:7.4.24-4.GA_redhat_00002.1.el8eap (rpm) before *
0:2.2.39-1.Final_redhat_00001.1.el9eap (rpm) before *
0:7.4.24-4.GA_redhat_00002.1.el9eap (rpm) before *
0:1.83.0-1.redhat_00001.1.el8eap (rpm) before *
0:33.0.0-2.jre_redhat_00003.1.el8eap (rpm) before *
0:4.0.6-1.redhat_00001.1.el8eap (rpm) before *
0:1.0.0-3.redhat_00009.1.el8eap (rpm) before *
0:2.0.2-1.Final_redhat_00001.1.el8eap (rpm) before *
0:2.3.23-1.SP3_redhat_00001.1.el8eap (rpm) before *
0:1.83.0-1.redhat_00001.1.el9eap (rpm) before *
0:33.0.0-2.jre_redhat_00003.1.el9eap (rpm) before *
0:4.0.6-1.redhat_00001.1.el9eap (rpm) before *
0:1.0.0-3.redhat_00009.1.el9eap (rpm) before *
0:2.0.2-1.Final_redhat_00001.1.el9eap (rpm) before *
0:2.3.23-1.SP3_redhat_00001.1.el9eap (rpm) before *
0:2.3.20-2.SP4_redhat_00001.1.el8eap (rpm) before *
0:2.3.20-2.SP4_redhat_00001.1.el9eap (rpm) before *
Timeline
| 2025-09-01: | Reported to Red Hat. |
| 2025-09-01: | Made public. |
References
www.kb.cert.org/vuls/id/767506
access.redhat.com/errata/RHSA-2025:23143 (RHSA-2025:23143)
access.redhat.com/errata/RHSA-2026:0383 (RHSA-2026:0383)
access.redhat.com/errata/RHSA-2026:0384 (RHSA-2026:0384)
access.redhat.com/errata/RHSA-2026:0386 (RHSA-2026:0386)
access.redhat.com/errata/RHSA-2026:3889 (RHSA-2026:3889)
access.redhat.com/errata/RHSA-2026:3891 (RHSA-2026:3891)
access.redhat.com/errata/RHSA-2026:3892 (RHSA-2026:3892)
access.redhat.com/errata/RHSA-2026:4915 (RHSA-2026:4915)
access.redhat.com/errata/RHSA-2026:4916 (RHSA-2026:4916)
access.redhat.com/errata/RHSA-2026:4917 (RHSA-2026:4917)
access.redhat.com/errata/RHSA-2026:4924 (RHSA-2026:4924)
access.redhat.com/security/cve/CVE-2025-9784
bugzilla.redhat.com/show_bug.cgi?id=2392306 (RHBZ#2392306)
github.com/undertow-io/undertow/pull/1778
github.com/undertow-io/undertow/releases/tag/2.2.38.Final
issues.redhat.com/browse/UNDERTOW-2598