Undertow MadeYouReset HTTP/2 DDoS Vulnerability
High severity
GitHub Reviewed
Published
Sep 2, 2025
to the GitHub Advisory Database
•
Updated Sep 2, 2025
Description
Published by the National Vulnerability Database
Sep 2, 2025
Published to the GitHub Advisory Database
Sep 2, 2025
Reviewed
Sep 2, 2025
Last updated
Sep 2, 2025
A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive server workload by repeatedly causing server-side stream aborts. While not a protocol bug, this highlights a common implementation weakness that can be exploited to cause a denial of service (DoS).
References