PT-2025-35569 · Undertow · Undertow

·

CVE-2025-9784

·

Published

2025-09-02

·

Updated

2026-08-19

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Undertow (affected versions not specified)
Description A flaw exists in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, known as the “MadeYouReset” attack, allows malicious clients to induce excessive server workload by repeatedly causing server-side stream aborts, potentially leading to a denial of service (DoS).
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Resource Exhaustion

Allocation of Resources Without Limits

Improper Resource Release

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-09670
CVE-2025-9784
GHSA-95H4-W6J8-2RP8
RHSA-2026:0383
RHSA-2026:0384
RHSA-2026:33371
RHSA-2026:33372
RHSA-2026:3889
RHSA-2026:3891
RHSA-2026:4915
RHSA-2026:4916
RHSA-2026:4917

Affected Products

Undertow