Description

A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive server workload by repeatedly causing server-side stream aborts. While not a protocol bug, this highlights a common implementation weakness that can be exploited to cause a denial of service (DoS).

INFO

Published Date :

2025-09-02T13:37:59.772Z

Last Modified :

2026-04-01T11:43:10.566Z

Source :

redhat
AFFECTED PRODUCTS

The following products are affected by CVE-2025-9784 vulnerability.

Vendors Products
Redhat
  • Apache Camel Hawtio
  • Apache Camel Spring Boot
  • Build Of Apache Camel For Spring Boot
  • Enterprise Linux
  • Fuse
  • Jboss Data Grid
  • Jboss Enterprise Application Platform
  • Jboss Enterprise Application Platform Els
  • Jboss Enterprise Application Platform Expansion Pack
  • Jboss Enterprise Bpms Platform
  • Jboss Fuse
  • Jbosseapxp
  • Process Automation
  • Red Hat Single Sign On
  • Single Sign-on
  • Undertow

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact