A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive server workload by repeatedly causing server-side stream aborts. While not a protocol bug, this highlights a common implementation weakness that can be exploited to cause a denial of service (DoS).
References
Configurations
Configuration 1 (hide)
|
History
24 Sep 2025, 14:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
CWE | CWE-770 |
10 Sep 2025, 18:59
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.0.0:*:*:*:*:*:*:* cpe:2.3:a:redhat:fuse:7.0.0:*:*:*:*:*:*:* cpe:2.3:a:redhat:jboss_enterprise_application_platform:8.0.0:*:*:*:*:*:*:* cpe:2.3:a:redhat:undertow:-:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:-:*:*:* cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:* cpe:2.3:a:redhat:single_sign-on:7.0:*:*:*:*:*:*:* cpe:2.3:a:redhat:jboss_enterprise_application_platform_expansion_pack:-:*:*:*:*:*:*:* cpe:2.3:a:redhat:build_of_apache_camel_for_spring_boot:-:*:*:*:*:*:*:* cpe:2.3:a:redhat:process_automation:7.0:*:*:*:*:*:*:* |
|
First Time |
Redhat single Sign-on
Redhat fuse Redhat enterprise Linux Redhat jboss Enterprise Application Platform Redhat build Of Apache Camel For Spring Boot Redhat process Automation Redhat Redhat jboss Enterprise Application Platform Expansion Pack Redhat undertow |
|
References | () https://access.redhat.com/security/cve/CVE-2025-9784 - Vendor Advisory | |
References | () https://bugzilla.redhat.com/show_bug.cgi?id=2392306 - Issue Tracking |
02 Sep 2025, 15:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-404 |
02 Sep 2025, 14:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-09-02 14:15
Updated : 2025-09-24 14:15
NVD link : CVE-2025-9784
Mitre link : CVE-2025-9784
CVE.ORG link : CVE-2025-9784
JSON object : View
Products Affected
redhat
- build_of_apache_camel_for_spring_boot
- process_automation
- undertow
- enterprise_linux
- jboss_enterprise_application_platform
- single_sign-on
- fuse
- jboss_enterprise_application_platform_expansion_pack