A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive server workload by repeatedly causing server-side stream aborts. While not a protocol bug, this highlights a common implementation weakness that can be exploited to cause a denial of service (DoS).
References
Link | Resource |
---|---|
https://access.redhat.com/security/cve/CVE-2025-9784 | Vendor Advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=2392306 | Issue Tracking |
Configurations
Configuration 1 (hide)
|
History
10 Sep 2025, 18:59
Type | Values Removed | Values Added |
---|---|---|
First Time |
Redhat jboss Enterprise Application Platform Expansion Pack
Redhat build Of Apache Camel For Spring Boot Redhat single Sign-on Redhat process Automation Redhat fuse Redhat undertow Redhat enterprise Linux Redhat jboss Enterprise Application Platform Redhat |
|
References | () https://access.redhat.com/security/cve/CVE-2025-9784 - Vendor Advisory | |
References | () https://bugzilla.redhat.com/show_bug.cgi?id=2392306 - Issue Tracking | |
CPE | cpe:2.3:a:redhat:single_sign-on:7.0:*:*:*:*:*:*:* cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.0.0:*:*:*:*:*:*:* cpe:2.3:a:redhat:jboss_enterprise_application_platform_expansion_pack:-:*:*:*:*:*:*:* cpe:2.3:a:redhat:jboss_enterprise_application_platform:8.0.0:*:*:*:*:*:*:* cpe:2.3:a:redhat:fuse:7.0.0:*:*:*:*:*:*:* cpe:2.3:a:redhat:process_automation:7.0:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:-:*:*:* cpe:2.3:a:redhat:undertow:-:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:* cpe:2.3:a:redhat:build_of_apache_camel_for_spring_boot:-:*:*:*:*:*:*:* |
02 Sep 2025, 15:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-404 |
02 Sep 2025, 14:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-09-02 14:15
Updated : 2025-09-10 18:59
NVD link : CVE-2025-9784
Mitre link : CVE-2025-9784
CVE.ORG link : CVE-2025-9784
JSON object : View
Products Affected
redhat
- single_sign-on
- undertow
- jboss_enterprise_application_platform
- process_automation
- fuse
- build_of_apache_camel_for_spring_boot
- jboss_enterprise_application_platform_expansion_pack
- enterprise_linux
CWE
CWE-404
Improper Resource Shutdown or Release