VDB
Sign up
HIGH7.5

GHSA-95h4-w6j8-2rp8

Undertow MadeYouReset HTTP/2 DDoS Vulnerability

Quick fix

GHSA-95h4-w6j8-2rp8 — io.undertow:undertow-core: upgrade to the fixed version with the command below.

# pom.xml: bump <version>2.2.38.Final</version> for io.undertow:undertow-core

Details

A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive server workload by repeatedly causing server-side stream aborts. While not a protocol bug, this highlights a common implementation weakness that can be exploited to cause a denial of service (DoS).

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/io.undertow:undertow-core
Introduced in: 0Fixed in: 2.2.38.Final
Fix# pom.xml: bump <version>2.2.38.Final</version> for io.undertow:undertow-core
Maven/io.undertow:undertow-core
Introduced in: 2.3.0.Alpha1Fixed in: 2.3.20.Final
Fix# pom.xml: bump <version>2.3.20.Final</version> for io.undertow:undertow-core

References