A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive server workload by repeatedly causing server-side stream aborts. While not a protocol bug, this highlights a common implementation weakness that can be exploited to cause a denial of service (DoS).
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| io.undertow:undertow-core(Maven) | 0 | 2.2.38.Final | N/A |
| io.undertow:undertow-core(Maven) | 2.3.0.Alpha1 | 2.3.20.Final | N/A |
CVSS Metrics