CVE-2025-9784

A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive server workload by repeatedly causing server-side stream aborts. While not a protocol bug, this highlights a common implementation weakness that can be exploited to cause a denial of service (DoS).
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:redhat:build_of_apache_camel_for_spring_boot:-:*:*:*:*:*:*:*
cpe:2.3:a:redhat:fuse:7.0.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.0.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform:8.0.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform_expansion_pack:-:*:*:*:*:*:*:*
cpe:2.3:a:redhat:process_automation:7.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:single_sign-on:7.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:undertow:-:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:-:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*

History

24 Sep 2025, 14:15

Type Values Removed Values Added
References
  • () https://github.com/undertow-io/undertow/pull/1778 -
  • () https://issues.redhat.com/browse/UNDERTOW-2598 -
CWE CWE-770

10 Sep 2025, 18:59

Type Values Removed Values Added
CPE cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.0.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:fuse:7.0.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform:8.0.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:undertow:-:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:-:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:single_sign-on:7.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform_expansion_pack:-:*:*:*:*:*:*:*
cpe:2.3:a:redhat:build_of_apache_camel_for_spring_boot:-:*:*:*:*:*:*:*
cpe:2.3:a:redhat:process_automation:7.0:*:*:*:*:*:*:*
First Time Redhat single Sign-on
Redhat fuse
Redhat enterprise Linux
Redhat jboss Enterprise Application Platform
Redhat build Of Apache Camel For Spring Boot
Redhat process Automation
Redhat
Redhat jboss Enterprise Application Platform Expansion Pack
Redhat undertow
References () https://access.redhat.com/security/cve/CVE-2025-9784 - () https://access.redhat.com/security/cve/CVE-2025-9784 - Vendor Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2392306 - () https://bugzilla.redhat.com/show_bug.cgi?id=2392306 - Issue Tracking

02 Sep 2025, 15:15

Type Values Removed Values Added
CWE CWE-400 CWE-404

02 Sep 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-02 14:15

Updated : 2025-09-24 14:15


NVD link : CVE-2025-9784

Mitre link : CVE-2025-9784

CVE.ORG link : CVE-2025-9784


JSON object : View

Products Affected

redhat

  • build_of_apache_camel_for_spring_boot
  • process_automation
  • undertow
  • enterprise_linux
  • jboss_enterprise_application_platform
  • single_sign-on
  • fuse
  • jboss_enterprise_application_platform_expansion_pack
CWE
CWE-770

Allocation of Resources Without Limits or Throttling

CWE-404

Improper Resource Shutdown or Release