CVE-2025-8671
Description
A flaw was found in multiple implementations of HTTP/2 where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive server workload by repeatedly causing server-side stream aborts. While not a protocol bug, this highlights a common implementation weakness that can be exploited to cause a denial of service (DoS).
Statement
This vulnerability is used to track additional modules, which may be vulnerable to the "MadeYouReset" attack. As Red Hat Product Security has not identified additional exposure, please reference these other vulnerabilities for detailed information: CVE-2025-48989, CVE-2025-55163, CVE-2025-5115, & CVE-2025-54500.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.