CVE-2025-8671

Pingora MadeYouReset HTTP/2 vulnerability

Description

A mismatch caused by client-triggered server-sent stream resets between HTTP/2 specifications and the internal architectures of some HTTP/2 implementations may result in excessive server resource consumption leading to denial-of-service (DoS). By opening streams and then rapidly triggering the server to reset them—using malformed frames or flow control errors—an attacker can exploit incorrect stream accounting. Streams reset by the server are considered closed at the protocol level, even though backend processing continues. This allows a client to cause the server to handle an unbounded number of concurrent streams on a single connection. This CVE will be updated as affected product details are released.

Metrics

Severity
none
PoC (publicly reported)
88.5 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
3.5 %
Moderate — model estimates 1-10% exploitation likelihood.
Published
2025-09-17 12:00 UTC

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • Apache

    Tomcat< 10.1.44

    fixed in 10.1.44

  • Apache

    Tomcat< 11.0.10

    fixed in 11.0.10

  • Apache

    Tomcat< 9.0.108

    fixed in 9.0.108

  • Atlassian

    Bamboo< 10.2.8

    fixed in 10.2.8

  • Atlassian

    Bamboo< 11.0.5

    fixed in 11.0.5

  • Atlassian

    Bamboo< 9.6.17

    fixed in 9.6.17

  • Atlassian

    Bitbucket< 10.0.2

    fixed in 10.0.2

  • Atlassian

    Bitbucket<8.19.25 (LTS)

  • Atlassian

    Bitbucket<9.4.13 (LTS)

  • Atlassian

    Jira< 10.3.12

    fixed in 10.3.12

  • Atlassian

    Jira< 11.1.1

    fixed in 11.1.1

  • Atlassian

    Jira< 9.12.28

    fixed in 9.12.28

  • Dell

    NetWorkerManagement Console <19.13.0.2

  • Dell

    NetWorkerManagement Web UI <19.13.0.2

  • Dell

    Secure Connect Gateway< 5.34.00.16

    fixed in 5.34.00.16

  • Dell

    Secure Connect GatewayAppliance <5.32.00.18

  • Eclipse

    Jetty< 10.0.26

    fixed in 10.0.26

  • Eclipse

    Jetty< 11.0.26

    fixed in 11.0.26

  • Eclipse

    Jetty< 12.0.25

    fixed in 12.0.25

  • Eclipse

    Jetty< 12.1.0.beta3

    fixed in 12.1.0.beta3

  • Eclipse

    Jetty< 9.4.58

    fixed in 9.4.58

  • HCL

    Commerce< 25.09.17.0

    fixed in 25.09.17.0

  • IBM

    Integration Bus10.1.0.0-10.1.0.6

  • IBM

    Storage Scale< 5.2.3.4

    fixed in 5.2.3.4

References & sources

IDCVE-2025-8671