CVE-2025-9784
Red Hat Red Hat build of Apache Camel 4.14.2 for Spring Boot 3.5.8, Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7, Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7
A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive server workload by repeatedly causing server-side stream aborts. While not a protocol bug, this highlights a common implementation weakness that can be exploited to cause a denial of service (DoS).
- CVSS
- 7.5
- EPSS
- 2.33% 81.8% percentile
- CISA KEV
- Not listed
- Published
- 2025.09.02