CVE-2025-9784
Executive Summary
CVE-2025-9784 exposes a flaw in Undertow where malformed client requests trigger server‑side stream resets without engaging abuse counters, enabling a "MadeYouReset" attack. Attackers can repeatedly cause stream aborts, inflating server workload and leading to denial of service. The issue is an implementation weakness rather than a protocol bug and is not yet listed in CISA KEV.
Authoritative CVE Metadata - CVSS Base Score: 7.5 (HIGH) - Published: 2025-09-02T14:15:36.593 - Last Modified: 2026-10-06T17:17:11.217
Original Description: A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive server workload by repeatedly causing server-side stream aborts. While not a protocol bug, this highlights a common implementation weakness that can be exploited to cause a denial of service (DoS).
"Every person, all the events of your life are there because you have drawn them there. What you choose to do with them is up to you."
— Richard Bach