CVE-2025-9784

A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive server workload by repeatedly causing server-side stream aborts. While not a protocol bug, this highlights a common implementation weakness that can be exploited to cause a denial of service (DoS).
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:redhat:build_of_apache_camel_for_spring_boot:-:*:*:*:*:*:*:*
cpe:2.3:a:redhat:fuse:7.0.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.0.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform:8.0.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform_expansion_pack:-:*:*:*:*:*:*:*
cpe:2.3:a:redhat:process_automation:7.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:single_sign-on:7.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:undertow:-:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:-:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*

History

24 Sep 2025, 14:15

Type Values Removed Values Added
References
  • () https://github.com/undertow-io/undertow/pull/1778 -
  • () https://issues.redhat.com/browse/UNDERTOW-2598 -
CWE CWE-770

10 Sep 2025, 18:59

Type Values Removed Values Added
First Time Redhat jboss Enterprise Application Platform
Redhat enterprise Linux
Redhat undertow
Redhat build Of Apache Camel For Spring Boot
Redhat
Redhat fuse
Redhat single Sign-on
Redhat process Automation
Redhat jboss Enterprise Application Platform Expansion Pack
References () https://access.redhat.com/security/cve/CVE-2025-9784 - () https://access.redhat.com/security/cve/CVE-2025-9784 - Vendor Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2392306 - () https://bugzilla.redhat.com/show_bug.cgi?id=2392306 - Issue Tracking
CPE cpe:2.3:a:redhat:single_sign-on:7.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.0.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:undertow:-:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:-:*:*:*
cpe:2.3:a:redhat:build_of_apache_camel_for_spring_boot:-:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform:8.0.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:fuse:7.0.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform_expansion_pack:-:*:*:*:*:*:*:*
cpe:2.3:a:redhat:process_automation:7.0:*:*:*:*:*:*:*

02 Sep 2025, 15:15

Type Values Removed Values Added
CWE CWE-400 CWE-404

02 Sep 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-02 14:15

Updated : 2025-09-24 14:15


NVD link : CVE-2025-9784

Mitre link : CVE-2025-9784

CVE.ORG link : CVE-2025-9784


JSON object : View

Products Affected

redhat

  • undertow
  • process_automation
  • enterprise_linux
  • fuse
  • jboss_enterprise_application_platform_expansion_pack
  • single_sign-on
  • jboss_enterprise_application_platform
  • build_of_apache_camel_for_spring_boot
CWE
CWE-770

Allocation of Resources Without Limits or Throttling

CWE-404

Improper Resource Shutdown or Release