CVE-2025-9784
7.5Red Hat · JBoss Enterprise Application Platform
A vulnerability in Undertow allows unauthenticated attackers to cause a denial of service via the MadeYouReset attack by bypassing server-side abuse counters.
Executive summary
An unauthenticated remote attacker can trigger a denial of service condition in Red Hat JBoss Enterprise Application Platform by exploiting a resource exhaustion vulnerability in the Undertow component.
Vulnerability
This vulnerability, known as the MadeYouReset attack, involves the submission of malformed client requests that trigger server-side stream resets without activating abuse-throttling mechanisms. This allows an unauthenticated attacker to induce excessive server workload and resource consumption.
Business impact
The primary risk associated with this vulnerability is a denial of service, which can lead to significant system downtime and operational disruption. Given the CVSS score of 7.5, the vulnerability is considered high severity due to the ease of exploitation over a network without requiring authentication. Such disruptions can impact the availability of critical business applications relying on the JBoss platform, potentially leading to productivity losses or service level agreement breaches.
Remediation
Immediate Action: Update the affected JBoss Enterprise Application Platform instances to the versions specified in the relevant Red Hat security advisories (e.g., 2.2.39.Final-redhat-00001 and later).
Proactive Monitoring: Monitor server logs and resource utilization metrics for sudden spikes in stream resets or unusual request patterns that may indicate a MadeYouReset attack attempt.
Compensating Controls: Implement rate limiting at the network or Web Application Firewall level to restrict the volume of requests from individual clients, which may mitigate the impact of this resource exhaustion flaw.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Organizations should prioritize the deployment of the vendor-provided updates to remediate this resource exhaustion vulnerability. Because the flaw is automatable and allows for remote denial of service without authentication, failing to patch leaves infrastructure susceptible to service instability and potential downtime.
More Red Hat CVEs
Sources
- RHSA-2025:23143 Vendor advisory
- RHSA-2026:0383 Vendor advisory
- RHSA-2026:0384 Vendor advisory
- RHSA-2026:0386 Vendor advisory
- RHSA-2026:33371 Vendor advisory
- RHSA-2026:33372 Vendor advisory
- RHSA-2026:3889 Vendor advisory
- RHSA-2026:3891 Vendor advisory