Disclosure summary
A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive server workload by repeatedly causing server-side stream aborts. While not a protocol bug, this highlights a common implementation weakness that can be exploited to cause a denial of service (DoS).
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-95h4-w6j8-2rp8
Open original source · Updated Oct 05, 2026
Undertow MadeYouReset HTTP/2 DDoS Vulnerability
Source severity: HIGH / 0
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| maven | io.undertow:undertow-core | < 2.2.38.Final | 2.2.38.Final |
| maven | io.undertow:undertow-core | >= 2.3.0.Alpha1, < 2.3.20.Final | 2.3.20.Final |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2025-09-02T11:31:08-04:00
MODIFIED 2026-10-05T20:32:49-04:00
INGESTED 2026-10-06T11:45:43-04:00