A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive server workload by repeatedly causing server-side stream aborts. While not a protocol bug, this highlights a common implementation weakness that can be exploited to cause a denial of service (DoS).
References
Configurations
Configuration 1 (hide)
|
History
24 Sep 2025, 14:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
|
| CWE | CWE-770 |
10 Sep 2025, 18:59
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Redhat jboss Enterprise Application Platform
Redhat enterprise Linux Redhat undertow Redhat build Of Apache Camel For Spring Boot Redhat Redhat fuse Redhat single Sign-on Redhat process Automation Redhat jboss Enterprise Application Platform Expansion Pack |
|
| References | () https://access.redhat.com/security/cve/CVE-2025-9784 - Vendor Advisory | |
| References | () https://bugzilla.redhat.com/show_bug.cgi?id=2392306 - Issue Tracking | |
| CPE | cpe:2.3:a:redhat:single_sign-on:7.0:*:*:*:*:*:*:* cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.0.0:*:*:*:*:*:*:* cpe:2.3:a:redhat:undertow:-:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:-:*:*:* cpe:2.3:a:redhat:build_of_apache_camel_for_spring_boot:-:*:*:*:*:*:*:* cpe:2.3:a:redhat:jboss_enterprise_application_platform:8.0.0:*:*:*:*:*:*:* cpe:2.3:a:redhat:fuse:7.0.0:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:* cpe:2.3:a:redhat:jboss_enterprise_application_platform_expansion_pack:-:*:*:*:*:*:*:* cpe:2.3:a:redhat:process_automation:7.0:*:*:*:*:*:*:* |
02 Sep 2025, 15:15
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-404 |
02 Sep 2025, 14:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-09-02 14:15
Updated : 2025-09-24 14:15
NVD link : CVE-2025-9784
Mitre link : CVE-2025-9784
CVE.ORG link : CVE-2025-9784
JSON object : View
Products Affected
redhat
- undertow
- process_automation
- enterprise_linux
- fuse
- jboss_enterprise_application_platform_expansion_pack
- single_sign-on
- jboss_enterprise_application_platform
- build_of_apache_camel_for_spring_boot
