CVE-2025-8671
published 2025-08-13CVE-2025-8671: A mismatch caused by client-triggered server-sent stream resets between HTTP/2 specifications and the internal architectures of some HTTP/2 implementations may…
PriorityP349high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
3.51%
87.9th percentile
A mismatch caused by client-triggered server-sent stream resets between HTTP/2 specifications and the internal architectures of some HTTP/2 implementations may result in excessive server resource consumption leading to denial-of-service (DoS). By opening streams and then rapidly triggering the server to reset them—using malformed frames or flow control errors—an attacker can exploit incorrect stream accounting. Streams reset by the server are considered closed at the protocol level, even though backend processing continues. This allows a client to cause the server to handle an unbounded number of concurrent streams on a single connection. This CVE will be updated as affected product details are released.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| amphp | http-server | >= 2.0.0-rc1 < 2.1.10 | 2.1.10 |
| amphp | http-server | >= 3.0.0-beta.1 < 3.4.4 | 3.4.4 |
| debian | h2o | < varnish 7.7.2-1 (forky) | varnish 7.7.2-1 (forky) |
| debian | haproxy | < varnish 7.7.2-1 (forky) | varnish 7.7.2-1 (forky) |
| debian | varnish | < varnish 7.7.2-1 (forky) | varnish 7.7.2-1 (forky) |
| fastly | h20 | — | — |
| powerdns | dnsdist | >= 0 < 1.9.10-1ubuntu0.1 | 1.9.10-1ubuntu0.1 |
| powerdns | dnsdist | >= 0 < 1.6.1-1ubuntu0.1~esm2 | 1.6.1-1ubuntu0.1~esm2 |
| powerdns | dnsdist | >= 0 < 1.8.3-2ubuntu0.1~esm1 | 1.8.3-2ubuntu0.1~esm1 |
| suse_linux | enterprise_desktop | >= 15 SP6 < 15 SP7 | 15 SP7 |
| suse_linux | enterprise_high_performance_computing | >= 15 < 15 SP5 | 15 SP5 |
| suse_linux | enterprise_high_performance_computing | >= 15 SP3 < 15 SP7 | 15 SP7 |
| suse_linux | enterprise_module_for_dev_tools | >= 15 SP3 < 15 SP7 | 15 SP7 |
| suse_linux | enterprise_module_for_development_tools | >= 15 SP2 < 15-SP5 | 15-SP5 |
| suse_linux | enterprise_module_for_package_hub | >= 15 SP5 < 15 SP7 | 15 SP7 |
| suse_linux | enterprise_server | >= 12 SP5 < 15 SP7 | 15 SP7 |
| suse_linux | enterprise_server_for_sap_applications | >= 15 SP6 < 15 SP7 | 15 SP7 |
| suse_linux | opensuse_leap | — | — |
| suse_linux | suse_manager_proxy | — | — |
| suse_linux | suse_manager_retail_branch_server | — | — |
| suse_linux | suse_manager_server | — | — |
| suse_linux | suse_manager_server_lts | — | — |
| varnish-cache | varnish | >= 0 < 7.7.2-1 | 7.7.2-1 |
| varnish_software | varnish_cache | 5.x – 7.71 | — |
| varnish_software | varnish_cache | 6.0LTS – 6.014 | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
ghsa7.5HIGH
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu3.7LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
DNSdist vulnerabilities
vendor_ubuntu·2026-02-12·CVSS 3.7
CVE-2025-30187 [LOW] DNSdist vulnerabilities
Title: DNSdist vulnerabilities
Summary: Several security issues were fixed in dnsdist.
It was discovered that HTTP/2, which is used/vendored by DNSdist, did not
properly account for resources when handling client-triggered stream
resets. An attacker could possibly use this issue to cause a
denial of service. (CVE-2025-8671)
It was discovered that DNSdist did not properly manage memory limits when
handling an unlimited number of queries on a single TCP connection. An
attacker could possibly use this issue to cause a denial of service.
(CVE-2025-30193)
It was discovered that DNSdist, when configured with the nghttp2 library,
did not correctly process certain DNS over HTTPS queries. An attacker
could possibly use this cause a denial of service. (CVE-2025-30187)
Instructions: In general,
Red Hat
upstream:
vendor_redhat·2025-08-13·CVSS 7.5
CVE-2025-8671 [HIGH] upstream:
upstream:
A mismatch caused by client-triggered server-sent stream resets between HTTP/2 specifications and the internal architectures of some HTTP/2 implementations may result in excessive server resource consumption leading to denial-of-service (DoS). By opening streams and then rapidly triggering the server to reset them—using malformed frames or flow control errors—an attacker can exploit incorrect stream accounting. Streams reset by the server are considered closed at the protocol level, even though backend processing continues. This allows a client to cause the server to handle an unbounded number of concurrent streams on a single connection. This CVE will be updated as affected product details are released.
A flaw was found in multiple implementations of HTTP/2 where malformed cli
Debian
CVE-2025-8671: h2o - A mismatch caused by client-triggered server-sent stream resets between HTTP/2 s...
vendor_debian·2025·CVSS 7.5
CVE-2025-8671 [HIGH] CVE-2025-8671: h2o - A mismatch caused by client-triggered server-sent stream resets between HTTP/2 s...
A mismatch caused by client-triggered server-sent stream resets between HTTP/2 specifications and the internal architectures of some HTTP/2 implementations may result in excessive server resource consumption leading to denial-of-service (DoS). By opening streams and then rapidly triggering the server to reset them—using malformed frames or flow control errors—an attacker can exploit incorrect stream accounting. Streams reset by the server are considered closed at the protocol level, even though backend processing continues. This allows a client to cause the server to handle an unbounded number of concurrent streams on a single connection. This CVE will be updated as affected product details are released.
Scope: local
bookworm: open
bullseye: open
OSV
dnsdist vulnerabilities
osv·2026-02-12·CVSS 3.7
CVE-2025-8671 [LOW] dnsdist vulnerabilities
dnsdist vulnerabilities
It was discovered that HTTP/2, which is used/vendored by DNSdist, did not
properly account for resources when handling client-triggered stream
resets. An attacker could possibly use this issue to cause a
denial of service. (CVE-2025-8671)
It was discovered that DNSdist did not properly manage memory limits when
handling an unlimited number of queries on a single TCP connection. An
attacker could possibly use this issue to cause a denial of service.
(CVE-2025-30193)
It was discovered that DNSdist, when configured with the nghttp2 library,
did not correctly process certain DNS over HTTPS queries. An attacker
could possibly use this cause a denial of service. (CVE-2025-30187)
GHSA
amphp/http-server affected by HTTP/2 DDoS vulnerability
ghsa·2026-02-10·CVSS 7.5
CVE-2025-8671 [HIGH] CWE-400 amphp/http-server affected by HTTP/2 DDoS vulnerability
amphp/http-server affected by HTTP/2 DDoS vulnerability
Versions of `amphp/http-server` prior to `3.4.4` for the 3.x release branch and prior to `2.1.10` for the 2.x release branch are vulnerable to the HTTP/2 "MadeYouReset" DoS attack described by CVE-2025-8671 and https://kb.cert.org/vuls/id/767506.
In versions `3.4.4` and `2.1.10`, stream reset protection has been refactored to account for the number of reset streams within a sliding time window.
Note that your application must expose HTTP/2 connections directly to be affected by this vulnerability. Servers behind a proxy using HTTP/1.x such as nginx are not affected.
OSV
amphp/http-server affected by HTTP/2 DDoS vulnerability
osv·2026-02-10·CVSS 7.5
CVE-2025-8671 [HIGH] amphp/http-server affected by HTTP/2 DDoS vulnerability
amphp/http-server affected by HTTP/2 DDoS vulnerability
Versions of `amphp/http-server` prior to `3.4.4` for the 3.x release branch and prior to `2.1.10` for the 2.x release branch are vulnerable to the HTTP/2 "MadeYouReset" DoS attack described by CVE-2025-8671 and https://kb.cert.org/vuls/id/767506.
In versions `3.4.4` and `2.1.10`, stream reset protection has been refactored to account for the number of reset streams within a sliding time window.
Note that your application must expose HTTP/2 connections directly to be affected by this vulnerability. Servers behind a proxy using HTTP/1.x such as nginx are not affected.
OSV
Pingora update for MadeYouReset HTTP/2 vulnerability
osv·2025-09-17·CVSS 7.5
CVE-2025-8671 [HIGH] Pingora update for MadeYouReset HTTP/2 vulnerability
Pingora update for MadeYouReset HTTP/2 vulnerability
Pingora deployments that include HTTP/2 server support may be affected by the vulnerability described in CVE-2025-8671. Under certain conditions, Pingora applications may allocate buffers before the HTTP/2 reset and resulting stream cancellation is processed by the server. Repeated resets can force excessive memory consumption and lead to denial-of-service.
**Impact**:
On affected versions, malicious clients could trigger unusually high memory consumption, which may result in service instability or process termination.
**Credits**:
Reported responsibly by security researcher [Gal Bar Nahum](https://github.com/galbarnahum) (@[galbarnahum](https://github.com/galbarnahum))
**Mitigation**:
This issue is addressed by ensuring Pingora uses
GHSA
Pingora update for MadeYouReset HTTP/2 vulnerability
ghsa·2025-09-17·CVSS 7.5
CVE-2025-8671 [HIGH] Pingora update for MadeYouReset HTTP/2 vulnerability
Pingora update for MadeYouReset HTTP/2 vulnerability
Pingora deployments that include HTTP/2 server support may be affected by the vulnerability described in CVE-2025-8671. Under certain conditions, Pingora applications may allocate buffers before the HTTP/2 reset and resulting stream cancellation is processed by the server. Repeated resets can force excessive memory consumption and lead to denial-of-service.
**Impact**:
On affected versions, malicious clients could trigger unusually high memory consumption, which may result in service instability or process termination.
**Credits**:
Reported responsibly by security researcher [Gal Bar Nahum](https://github.com/galbarnahum) (@[galbarnahum](https://github.com/galbarnahum))
**Mitigation**:
This issue is addressed by ensuring Pingora uses
OSV
Pingora MadeYouReset HTTP/2 vulnerability
osv·2025-09-17·CVSS 7.5
CVE-2025-8671 [HIGH] Pingora MadeYouReset HTTP/2 vulnerability
Pingora MadeYouReset HTTP/2 vulnerability
Pingora deployments using versions prior to 0.6.0 that include HTTP/2 server support may be affected by the vulnerability described in CVE-2025-8671. Under certain conditions, Pingora applications may allocate buffers before the HTTP/2 reset and resulting stream cancellation is processed by the server. Repeated resets can force excessive memory consumption and lead to denial-of-service.
On affected versions, malicious clients could trigger unusually high memory consumption, which may result in service instability or process termination.
This issue is addressed by ensuring Pingora uses patched versions of HTTP/2 dependencies that include reset-handling safeguards to release connection resources before excessive memory buildup. Users are requested
OSV
CVE-2025-8671: A mismatch caused by client-triggered server-sent stream resets between HTTP/2 specifications and the internal architectures of some HTTP/2 implementa
osv·2025-08-13·CVSS 7.5
CVE-2025-8671 [HIGH] CVE-2025-8671: A mismatch caused by client-triggered server-sent stream resets between HTTP/2 specifications and the internal architectures of some HTTP/2 implementa
A mismatch caused by client-triggered server-sent stream resets between HTTP/2 specifications and the internal architectures of some HTTP/2 implementations may result in excessive server resource consumption leading to denial-of-service (DoS). By opening streams and then rapidly triggering the server to reset them—using malformed frames or flow control errors—an attacker can exploit incorrect stream accounting. Streams reset by the server are considered closed at the protocol level, even though backend processing continues. This allows a client to cause the server to handle an unbounded number of concurrent streams on a single connection. This CVE will be updated as affected product details are released.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://galbarnahum.com/made-you-resethttps://github.com/h2o/h2o/commit/4729b661e3c6654198d2cc62997e1af58bef4b80https://github.com/h2o/h2o/security/advisories/GHSA-mrjm-qq9m-9mjqhttps://gitlab.isc.org/isc-projects/bind9/-/issues/5325https://kb.cert.org/vuls/id/767506https://support2.windriver.com/index.php?page=security-noticeshttps://varnish-cache.org/security/VSV00017.htmlhttps://www.fastlystatus.com/incident/377810https://www.suse.com/support/kb/doc/?id=000021980http://www.openwall.com/lists/oss-security/2025/08/13/6http://www.openwall.com/lists/oss-security/2025/09/18/1https://deepness-lab.org/publications/madeyoureset/https://github.com/Kong/kong/discussions/14731https://github.com/envoyproxy/envoy/issues/40739https://github.com/varnish/hitch/issues/397https://www.imperva.com/blog/madeyoureset-turning-http-2-server-against-itself/https://www.kb.cert.org/vuls/id/767506https://gitlab.isc.org/isc-projects/bind9/-/issues/5325
2025-08-13
Published