CVE-2025-9784High· 7.5▾ MidnightPoC availableA flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive serv…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 41.3 · likelihood 0.5 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
2.2%
2.2% → 2.3%
1 GitHub repo
A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive server workload by repeatedly causing server-side stream aborts. While not a protocol bug, this highlights a common implementation weakness that can be exploited to cause a denial of service (DoS).
build_of_apache_camel_for_spring_bootfuse = 7.0.0jboss_enterprise_application_platform = 7.0.0jboss_enterprise_application_platform = 8.0.0jboss_enterprise_application_platform_expansion_packprocess_automation = 7.0single_sign-on = 7.0undertowenterprise_linux = 8.0enterprise_linux = 9.0Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-12543Critical· 9.6A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications
CVE-2026-16100Medium· 6.5A flaw was found in the user-event metrics recording of Keycloak
CVE-2023-5379High· 7.5A flaw was found in Undertow
CVE-2023-6563High· 7.7An unconstrained memory consumption vulnerability was discovered in Keycloak
CVE-2026-90713Low· 3.3A security flaw has been discovered in vllm-project vLLM up to 0.29.0
CVE-2018-8120High· 7.0An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows Server 2008, Windows 7, Windows Serve…