PT-2025-32984 · Http/2+3 · Http/2+3

Anat Bremler-Barr

+2

·

Published

2025-08-13

·

Updated

2026-06-06

·

CVE-2025-8671

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions AMPHP (affected versions not specified) Apache Tomcat (affected versions not specified) Eclipse Foundation (affected versions not specified) F5 (affected versions not specified) Fastly (affected versions not specified) gRPC (affected versions not specified) Mozilla (affected versions not specified) Netty (affected versions not specified) Suse Linux (affected versions not specified) Varnish Cache (affected versions not specified) Wind River (affected versions not specified) Zephyr Project (affected versions not specified)
Description A mismatch between HTTP/2 specifications and the internal architectures of some implementations leads to incorrect stream accounting. By opening streams and rapidly triggering the server to reset them using malformed frames or flow control errors, a remote attacker can cause excessive server resource consumption. This occurs because streams reset by the server are considered closed at the protocol level, while backend processing continues, allowing a client to force the server to handle an unbounded number of concurrent streams on a single connection. This issue, dubbed MadeYouReset, can be used to launch massive denial-of-service (DoS) attacks and bypasses existing Rapid Reset mitigations by tricking the server into resetting its own stream counters. The attack traffic often blends with legitimate traffic, making detection difficult.
Recommendations Update Apache Tomcat to the latest patched version. Update F5 to the latest patched version. Update Fastly to the latest patched version. Update Varnish Cache to the latest patched version. Implement rate-limiting and anomaly detection to identify and block malicious HTTP/2 traffic patterns. At the moment, there is no information about a newer version that contains a fix for AMPHP, Eclipse Foundation, gRPC, Mozilla, Netty, Suse Linux, Wind River, and Zephyr Project.

Exploit

Fix

DoS

Improper Resource Release

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-09848
CVE-2025-8671
GHSA-MRJM-QQ9M-9MJQ
MGASA-2025-0239
OESA-2025-2166
OESA-2025-2167
OESA-2025-2185
OESA-2025-2186
OESA-2025-2187
OESA-2025-2188
OESA-2025-2189
OESA-2025-2238
OESA-2025-2253
OESA-2025-2464
OPENSUSE-SU-2025:15448-1
OPENSUSE-SU-2026:10219-1
OPENSUSE-SU-2026:20461-1
RUSTSEC-2025-0070
SUSE-SU-2026:0888-1
SUSE-SU-2026:20995-1
USN-8037-1

Affected Products

Debian
Http/2
Linuxmint
Ubuntu