PT-2025-35569 · Undertow · Undertow

Osidb Bzimport

·

Published

2025-09-02

·

Updated

2026-03-19

·

CVE-2025-9784

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Undertow (affected versions not specified)
Description A flaw exists in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, known as the “MadeYouReset” attack, allows malicious clients to induce excessive server workload by repeatedly causing server-side stream aborts, potentially leading to a denial of service (DoS).
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Allocation of Resources Without Limits

Resource Exhaustion

Improper Resource Release

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-9784
GHSA-95H4-W6J8-2RP8
RHSA-2026:0383
RHSA-2026:0384
RHSA-2026:3889
RHSA-2026:3891
RHSA-2026:4915
RHSA-2026:4916
RHSA-2026:4917

Affected Products

Undertow