CVE-2025-55163
published 2025-08-13CVE-2025-55163: Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.124.Final and 4.2.4.Final, Netty is vulnerable to MadeYouReset…
PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.05%
60.5th percentile
Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.124.Final and 4.2.4.Final, Netty is vulnerable to MadeYouReset DDoS. This is a logical vulnerability in the HTTP/2 protocol, that uses malformed HTTP/2 control frames in order to break the max concurrent streams limit - which results in resource exhaustion and distributed denial of service. This issue has been patched in versions 4.1.124.Final and 4.2.4.Final.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | netty | < netty 1:4.1.48-7+deb12u2 (bookworm) | netty 1:4.1.48-7+deb12u2 (bookworm) |
| netty | netty | < 4.1.124.Final | 4.1.124.Final |
| netty | netty | < 4.2.4.Final | 4.2.4.Final |
| netty | netty | < 4.1.124 | 4.1.124 |
| netty | netty | >= 0 < 1:4.1.48-4+deb11u3 | 1:4.1.48-4+deb11u3 |
| netty | netty | >= 0 < 1:4.1.48-7+deb12u2 | 1:4.1.48-7+deb12u2 |
| netty | netty | >= 0 < 1:4.1.48-10+deb13u1 | 1:4.1.48-10+deb13u1 |
| netty | netty | >= 0 < 1:4.1.48-11 | 1:4.1.48-11 |
| netty | netty | >= 4.2.0 < 4.2.4 | 4.2.4 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv4.08.2HIGHCVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv8.2HIGH
vendor_debian8.2HIGH
vendor_redhat8.2HIGH
vendor_oracle4.9HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2025-55163: Netty is an asynchronous, event-driven network application framework
osv·2025-08-13·CVSS 8.2
CVE-2025-55163 [HIGH] CVE-2025-55163: Netty is an asynchronous, event-driven network application framework
Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.124.Final and 4.2.4.Final, Netty is vulnerable to MadeYouReset DDoS. This is a logical vulnerability in the HTTP/2 protocol, that uses malformed HTTP/2 control frames in order to break the max concurrent streams limit - which results in resource exhaustion and distributed denial of service. This issue has been patched in versions 4.1.124.Final and 4.2.4.Final.
GHSA
Netty affected by MadeYouReset HTTP/2 DDoS vulnerability
ghsa·2025-08-13
CVE-2025-55163 [HIGH] CWE-770 Netty affected by MadeYouReset HTTP/2 DDoS vulnerability
Netty affected by MadeYouReset HTTP/2 DDoS vulnerability
Below is a technical explanation of a newly discovered vulnerability in HTTP/2, which we refer to as “MadeYouReset.”
### MadeYouReset Vulnerability Summary
The MadeYouReset DDoS vulnerability is a logical vulnerability in the HTTP/2 protocol, that uses malformed HTTP/2 control frames in order to break the max concurrent streams limit - which results in resource exhaustion and distributed denial of service.
### Mechanism
The vulnerability uses malformed HTTP/2 control frames, or malformed flow, in order to make the server reset streams created by the client (using the RST_STREAM frame).
The vulnerability could be triggered by several primitives, defined by the RFC of HTTP/2 (RFC 9113). The Primitives are:
1. WINDOW_UPDATE frame wit
OSV
Netty affected by MadeYouReset HTTP/2 DDoS vulnerability
osv·2025-08-13
CVE-2025-55163 [HIGH] Netty affected by MadeYouReset HTTP/2 DDoS vulnerability
Netty affected by MadeYouReset HTTP/2 DDoS vulnerability
Below is a technical explanation of a newly discovered vulnerability in HTTP/2, which we refer to as “MadeYouReset.”
### MadeYouReset Vulnerability Summary
The MadeYouReset DDoS vulnerability is a logical vulnerability in the HTTP/2 protocol, that uses malformed HTTP/2 control frames in order to break the max concurrent streams limit - which results in resource exhaustion and distributed denial of service.
### Mechanism
The vulnerability uses malformed HTTP/2 control frames, or malformed flow, in order to make the server reset streams created by the client (using the RST_STREAM frame).
The vulnerability could be triggered by several primitives, defined by the RFC of HTTP/2 (RFC 9113). The Primitives are:
1. WINDOW_UPDATE frame wit
Oracle
Oracle Oracle Communications Risk Matrix: Core (Netty) — CVE-2025-55163
vendor_oracle·2026-01-15·CVSS 4.9
CVE-2025-55163 [HIGH] Oracle Oracle Communications Risk Matrix: Core (Netty) — CVE-2025-55163
Oracle Oracle Communications Risk Matrix: Core (Netty) vulnerability
CVE: CVE-2025-55163
CVSS: 4.9
Protocol: HTTP/2
Remote exploit: No
Affected versions: Network
Advisory: cpujan2026 (JAN 2026)
Oracle
Oracle Oracle Commerce Risk Matrix: Tools And Frameworks (Netty) — CVE-2025-55163
vendor_oracle·2025-10-15·CVSS 4.9
CVE-2025-55163 [HIGH] Oracle Oracle Commerce Risk Matrix: Tools And Frameworks (Netty) — CVE-2025-55163
Oracle Oracle Commerce Risk Matrix: Tools And Frameworks (Netty) vulnerability
CVE: CVE-2025-55163
CVSS: 4.9
Protocol: HTTP/2
Remote exploit: No
Affected versions: Network
Advisory: cpuoct2025 (OCT 2025)
Red Hat
upstream:
vendor_redhat·2025-08-13·CVSS 7.5
CVE-2025-8671 [HIGH] upstream:
upstream:
A mismatch caused by client-triggered server-sent stream resets between HTTP/2 specifications and the internal architectures of some HTTP/2 implementations may result in excessive server resource consumption leading to denial-of-service (DoS). By opening streams and then rapidly triggering the server to reset them—using malformed frames or flow control errors—an attacker can exploit incorrect stream accounting. Streams reset by the server are considered closed at the protocol level, even though backend processing continues. This allows a client to cause the server to handle an unbounded number of concurrent streams on a single connection. This CVE will be updated as affected product details are released.
A flaw was found in multiple implementations of HTTP/2 where malformed cli
Red Hat
netty: netty-codec-http2: Netty MadeYouReset HTTP/2 DDoS Vulnerability
vendor_redhat·2025-08-13·CVSS 8.2
CVE-2025-55163 [HIGH] CWE-770 netty: netty-codec-http2: Netty MadeYouReset HTTP/2 DDoS Vulnerability
netty: netty-codec-http2: Netty MadeYouReset HTTP/2 DDoS Vulnerability
Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.124.Final and 4.2.4.Final, Netty is vulnerable to MadeYouReset DDoS. This is a logical vulnerability in the HTTP/2 protocol, that uses malformed HTTP/2 control frames in order to break the max concurrent streams limit - which results in resource exhaustion and distributed denial of service. This issue has been patched in versions 4.1.124.Final and 4.2.4.Final.
A flaw was found in Netty where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive server workload by repeatedly causing serv
Debian
CVE-2025-55163: netty - Netty is an asynchronous, event-driven network application framework. Prior to v...
vendor_debian·2025·CVSS 8.2
CVE-2025-55163 [HIGH] CVE-2025-55163: netty - Netty is an asynchronous, event-driven network application framework. Prior to v...
Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.124.Final and 4.2.4.Final, Netty is vulnerable to MadeYouReset DDoS. This is a logical vulnerability in the HTTP/2 protocol, that uses malformed HTTP/2 control frames in order to break the max concurrent streams limit - which results in resource exhaustion and distributed denial of service. This issue has been patched in versions 4.1.124.Final and 4.2.4.Final.
Scope: local
bookworm: resolved (fixed in 1:4.1.48-7+deb12u2)
bullseye: resolved (fixed in 1:4.1.48-4+deb11u3)
forky: resolved (fixed in 1:4.1.48-11)
sid: resolved (fixed in 1:4.1.48-11)
trixie: resolved (fixed in 1:4.1.48-10+deb13u1)
No detection rules found.
No public exploits indexed.
2025-08-13
Published