High severity7.5OSV Advisory· Published Sep 2, 2025· Updated Aug 19, 2026
CVE-2025-9784
CVE-2025-9784
Description
A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive server workload by repeatedly causing server-side stream aborts. While not a protocol bug, this highlights a common implementation weakness that can be exploited to cause a denial of service (DoS).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
io.undertow:undertow-coreMaven | < 2.2.38.Final | 2.2.38.Final |
io.undertow:undertow-coreMaven | >= 2.3.0.Alpha1, < 2.3.20.Final | 2.3.20.Final |
Affected products
22- Range: 1.0.0.Alpha1, 1.0.0.Alpha10, 1.0.0.Alpha11, …
- cpe:2.3:a:redhat:build_of_apache_camel_for_spring_boot:-:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.0.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:jboss_enterprise_application_platform:8.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:jboss_enterprise_application_platform_expansion_pack:-:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:process_automation:7.0:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:single_sign-on:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:-:*:*:*+ 1 more
- cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:-:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
- osv-coords11 versionspkg:apk/chainguard/wildflypkg:apk/chainguard/wildfly-openjdk-17pkg:apk/chainguard/wildfly-openjdk-17-compatpkg:apk/chainguard/wildfly-openjdk-21pkg:apk/chainguard/wildfly-openjdk-21-compatpkg:apk/wolfi/wildflypkg:apk/wolfi/wildfly-openjdk-17pkg:apk/wolfi/wildfly-openjdk-17-compatpkg:apk/wolfi/wildfly-openjdk-21pkg:apk/wolfi/wildfly-openjdk-21-compatpkg:maven/io.undertow/undertow-core
< 38.0.0-r0+ 10 more
- (no CPE)range: < 38.0.0-r0
- (no CPE)range: < 38.0.0-r0
- (no CPE)range: < 38.0.0-r0
- (no CPE)range: < 38.0.0-r0
- (no CPE)range: < 38.0.0-r0
- (no CPE)range: < 38.0.0-r0
- (no CPE)range: < 38.0.0-r0
- (no CPE)range: < 38.0.0-r0
- (no CPE)range: < 38.0.0-r0
- (no CPE)range: < 38.0.0-r0
- (no CPE)range: < 2.2.38.Final
Patches
Vulnerability mechanics
References
26- access.redhat.com/security/cve/CVE-2025-9784nvdVendor AdvisoryWEB
- github.com/advisories/GHSA-95h4-w6j8-2rp8ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2025-9784ghsaADVISORY
- access.redhat.com/errata/RHSA-2025:23143nvdWEB
- access.redhat.com/errata/RHSA-2026:0383nvdWEB
- access.redhat.com/errata/RHSA-2026:0384nvdWEB
- access.redhat.com/errata/RHSA-2026:0386nvdWEB
- access.redhat.com/errata/RHSA-2026:33371nvdWEB
- access.redhat.com/errata/RHSA-2026:33372nvdWEB
- access.redhat.com/errata/RHSA-2026:3889nvdWEB
- access.redhat.com/errata/RHSA-2026:3891nvdWEB
- access.redhat.com/errata/RHSA-2026:3892nvdWEB
- access.redhat.com/errata/RHSA-2026:4915nvdWEB
- access.redhat.com/errata/RHSA-2026:4916nvdWEB
- access.redhat.com/errata/RHSA-2026:4917nvdWEB
- access.redhat.com/errata/RHSA-2026:4924nvdWEB
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingWEB
- github.com/undertow-io/undertow/pull/1778nvdWEB
- github.com/undertow-io/undertow/pull/1802ghsaWEB
- github.com/undertow-io/undertow/pull/1803ghsaWEB
- github.com/undertow-io/undertow/pull/1804ghsaWEB
- github.com/undertow-io/undertow/pull/1805ghsaWEB
- github.com/undertow-io/undertow/releases/tag/2.2.38.FinalnvdWEB
- issues.redhat.com/browse/UNDERTOW-2598nvdWEB
- kb.cert.org/vuls/id/767506nvdWEB
- www.kb.cert.org/vuls/id/767506nvdWEB
News mentions
0No linked articles in our index yet.