CVE-2025-54500
published 2025-08-13CVE-2025-54500: An HTTP/2 implementation flaw allows a denial-of-service (DoS) that uses malformed HTTP/2 control frames in order to break the max concurrent streams limit…
PriorityP427medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
0.47%
38.4th percentile
An HTTP/2 implementation flaw allows a denial-of-service (DoS) that uses malformed HTTP/2 control frames in order to break the max concurrent streams limit (HTTP/2 MadeYouReset Attack).
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected
125 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | big-ip | >= 15.1.0 < * | * |
| f5 | big-ip | >= 16.1.0 < * | * |
| f5 | big-ip | >= 17.1.0 < * | * |
| f5 | big-ip | >= 17.5.0 < * | * |
| f5 | big-ip_aam | — | — |
| f5 | big-ip_access_policy_manager | >= 15.1.0 < 15.1.10.8 | 15.1.10.8 |
| f5 | big-ip_access_policy_manager | >= 16.1.0 < 16.1.6.1 | 16.1.6.1 |
| f5 | big-ip_access_policy_manager | >= 17.1.0 < 17.1.3 | 17.1.3 |
| f5 | big-ip_access_policy_manager | >= 17.5.0 < 17.5.1.2 | 17.5.1.2 |
| f5 | big-ip_advanced_firewall_manager | >= 15.1.0 < 15.1.10.8 | 15.1.10.8 |
| f5 | big-ip_advanced_firewall_manager | >= 16.1.0 < 16.1.6.1 | 16.1.6.1 |
| f5 | big-ip_advanced_firewall_manager | >= 17.1.0 < 17.1.3 | 17.1.3 |
| f5 | big-ip_advanced_firewall_manager | >= 17.5.0 < 17.5.1.2 | 17.5.1.2 |
| f5 | big-ip_advanced_waf | — | — |
| f5 | big-ip_advanced_web_application_firewall | >= 15.1.0 < 15.1.10.8 | 15.1.10.8 |
| f5 | big-ip_advanced_web_application_firewall | >= 16.1.0 < 16.1.6.1 | 16.1.6.1 |
| f5 | big-ip_advanced_web_application_firewall | >= 17.1.0 < 17.1.3 | 17.1.3 |
| f5 | big-ip_advanced_web_application_firewall | >= 17.5.0 < 17.5.1.2 | 17.5.1.2 |
| f5 | big-ip_afm | — | — |
| f5 | big-ip_analytics | — | — |
| f5 | big-ip_analytics | >= 15.1.0 < 15.1.10.8 | 15.1.10.8 |
| f5 | big-ip_analytics | >= 16.1.0 < 16.1.6.1 | 16.1.6.1 |
| f5 | big-ip_analytics | >= 17.1.0 < 17.1.3 | 17.1.3 |
| f5 | big-ip_analytics | >= 17.5.0 < 17.5.1.2 | 17.5.1.2 |
| f5 | big-ip_apm | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
nvdv4.06.9MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
F5
CVE-2025-54500: An HTTP/2 implementation flaw allows a denial-of-service (DoS) that uses malformed HTTP/2 control frames in order to ...
vendor_f5·2025-08-13·CVSS 5.3
CVE-2025-54500 [MEDIUM] CWE-770 CVE-2025-54500: An HTTP/2 implementation flaw allows a denial-of-service (DoS) that uses malformed HTTP/2 control frames in order to ...
CVE-2025-54500: An HTTP/2 implementation flaw allows a denial-of-service (DoS) that uses malformed HTTP/2 control frames in order to ...
An HTTP/2 implementation flaw allows a denial-of-service (DoS) that uses malformed HTTP/2 control frames in order to break the max concurrent streams limit (HTTP/2 MadeYouReset Attack).
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected Products: BIG-IP AAM, BIG-IP AFM, BIG-IP APM, BIG-IP ASM, BIG-IP AVR, BIG-IP Advanced WAF, BIG-IP Analytics, BIG-IP CGNAT, BIG-IP DHD, BIG-IP DNS, BIG-IP Edge Gateway, BIG-IP FPS, BIG-IP GTM, BIG-IP LTM, BIG-IP Link Controller, BIG-IP Next CNF, BIG-IP Next Central Manager, BIG-IP PEM, BIG-IP SSLO, BIG-IP WebAccelerator, BIG-IP WebSafe, Big-Ip Automation Toolchain, Big-
Red Hat
upstream:
vendor_redhat·2025-08-13·CVSS 7.5
CVE-2025-8671 [HIGH] upstream:
upstream:
A mismatch caused by client-triggered server-sent stream resets between HTTP/2 specifications and the internal architectures of some HTTP/2 implementations may result in excessive server resource consumption leading to denial-of-service (DoS). By opening streams and then rapidly triggering the server to reset them—using malformed frames or flow control errors—an attacker can exploit incorrect stream accounting. Streams reset by the server are considered closed at the protocol level, even though backend processing continues. This allows a client to cause the server to handle an unbounded number of concurrent streams on a single connection. This CVE will be updated as affected product details are released.
A flaw was found in multiple implementations of HTTP/2 where malformed cli
Red Hat
nginx: HTTP/2 Vulnerability
vendor_redhat·2025-08-13·CVSS 6.9
CVE-2025-54500 [MEDIUM] CWE-770 nginx: HTTP/2 Vulnerability
nginx: HTTP/2 Vulnerability
An HTTP/2 implementation flaw allows a denial-of-service (DoS) that uses malformed HTTP/2 control frames in order to break the max concurrent streams limit (HTTP/2 MadeYouReset Attack).
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
A flaw was found in F5 products, including NGINX, where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive server workload by repeatedly causing server-side stream aborts. While not a protocol bug, this highlights a common implementation weakness that can be exploited to cause a denial of service (DoS).
Statement: No versions of NGINX used
GHSA
GHSA-q678-fxj6-jj99: An HTTP/2 implementation flaw allows a denial-of-service (DoS) that uses malformed HTTP/2 control frames in order to break the max concurrent streams
ghsa_unreviewed·2025-08-13
CVE-2025-54500 [MEDIUM] CWE-770 GHSA-q678-fxj6-jj99: An HTTP/2 implementation flaw allows a denial-of-service (DoS) that uses malformed HTTP/2 control frames in order to break the max concurrent streams
An HTTP/2 implementation flaw allows a denial-of-service (DoS) that uses malformed HTTP/2 control frames in order to break the max concurrent streams limit (HTTP/2 MadeYouReset Attack).
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-08-13
Published