CVE-2025-9784

7.5

Red Hat · JBoss Enterprise Application Platform

A vulnerability in Undertow allows unauthenticated attackers to cause a denial of service via the MadeYouReset attack by bypassing server-side abuse counters.

Executive summary

An unauthenticated remote attacker can trigger a denial of service condition in Red Hat JBoss Enterprise Application Platform by exploiting a resource exhaustion vulnerability in the Undertow component.

Vulnerability

This vulnerability, known as the MadeYouReset attack, involves the submission of malformed client requests that trigger server-side stream resets without activating abuse-throttling mechanisms. This allows an unauthenticated attacker to induce excessive server workload and resource consumption.

Business impact

The primary risk associated with this vulnerability is a denial of service, which can lead to significant system downtime and operational disruption. Given the CVSS score of 7.5, the vulnerability is considered high severity due to the ease of exploitation over a network without requiring authentication. Such disruptions can impact the availability of critical business applications relying on the JBoss platform, potentially leading to productivity losses or service level agreement breaches.

Remediation

Immediate Action: Update the affected JBoss Enterprise Application Platform instances to the versions specified in the relevant Red Hat security advisories (e.g., 2.2.39.Final-redhat-00001 and later).

Proactive Monitoring: Monitor server logs and resource utilization metrics for sudden spikes in stream resets or unusual request patterns that may indicate a MadeYouReset attack attempt.

Compensating Controls: Implement rate limiting at the network or Web Application Firewall level to restrict the volume of requests from individual clients, which may mitigate the impact of this resource exhaustion flaw.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Organizations should prioritize the deployment of the vendor-provided updates to remediate this resource exhaustion vulnerability. Because the flaw is automatable and allows for remote denial of service without authentication, failing to patch leaves infrastructure susceptible to service instability and potential downtime.

More Red Hat CVEs

Sources