A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive server workload by repeatedly causing server-side stream aborts. While not a protocol bug, this highlights a common implementation weakness that can be exploited to cause a denial of service (DoS).
References
Configurations
No configuration.
History
02 Sep 2025, 15:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-404 |
02 Sep 2025, 14:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-09-02 14:15
Updated : 2025-09-02 15:55
NVD link : CVE-2025-9784
Mitre link : CVE-2025-9784
CVE.ORG link : CVE-2025-9784
JSON object : View
Products Affected
No product.
CWE
CWE-404
Improper Resource Shutdown or Release