---
id: CVE-2025-9784
title: >-
  A flaw was found in Undertow where malformed client requests can trigger
  server-side stream resets without triggering abuse counters
summary: >-
  A flaw was found in Undertow where malformed client requests can trigger
  server-side stream resets without triggering abuse counters. This issue,
  referred to as the "MadeYouReset" attack, allows malicious clients to induce
  excessive serv…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-770
  - CWE-404
vendor: redhat
product: build_of_apache_camel_for_spring_boot
affected:
  - build_of_apache_camel_for_spring_boot
  - fuse = 7.0.0
  - jboss_enterprise_application_platform = 7.0.0
  - jboss_enterprise_application_platform = 8.0.0
  - jboss_enterprise_application_platform_expansion_pack
  - process_automation = 7.0
  - single_sign-on = 7.0
  - undertow
  - enterprise_linux = 8.0
  - enterprise_linux = 9.0
published: '2025-09-02'
updated: '2026-06-25'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-9784'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2025:23143'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:0383'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:0384'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:0386'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:3889'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:3891'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:3892'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:4915'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:4916'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:4917'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:4924'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2025-9784'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2392306'
    label: secalert@redhat.com
  - url: 'https://github.com/undertow-io/undertow/pull/1778'
    label: secalert@redhat.com
  - url: 'https://github.com/undertow-io/undertow/releases/tag/2.2.38.Final'
    label: secalert@redhat.com
  - url: 'https://issues.redhat.com/browse/UNDERTOW-2598'
    label: secalert@redhat.com
  - url: 'https://kb.cert.org/vuls/id/767506'
    label: secalert@redhat.com
  - url: 'https://www.kb.cert.org/vuls/id/767506'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - exploit-available
epss: 0.02325
epssPercentile: 0.82766
ingestedAt: '2026-06-29T13:24:34.407Z'
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/drackyjr/CVE-2025-9784'
  checkedAt: '2026-09-24T07:52:54.202Z'
exploitAvailable: true
---

## Overview

A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive server workload by repeatedly causing server-side stream aborts. While not a protocol bug, this highlights a common implementation weakness that can be exploited to cause a denial of service (DoS).

## Affected

- `build_of_apache_camel_for_spring_boot`
- `fuse = 7.0.0`
- `jboss_enterprise_application_platform = 7.0.0`
- `jboss_enterprise_application_platform = 8.0.0`
- `jboss_enterprise_application_platform_expansion_pack`
- `process_automation = 7.0`
- `single_sign-on = 7.0`
- `undertow`
- `enterprise_linux = 8.0`
- `enterprise_linux = 9.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
