CVE-2025-9784: Red Hat Build Of Apache Camel For Spring Boot

High severity, CVSS 7.5. EPSS: 2.3% chance of exploitation in the next 30 days.

A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive server workload by repeatedly causing server-side stream aborts. While not a protocol bug, this highlights a common implementation weakness that can be exploited to cause a denial of service (DoS).

Affected products

  • Red Hat Build Of Apache Camel For Spring Boot: affected versions not specified
  • Red Hat Enterprise Linux: version 8.0 only; version 9.0 only
  • Red Hat Fuse: version 7.0.0 only
  • Red Hat JBoss Enterprise Application Platform: version 7.0.0 only; version 8.0.0 only
  • Red Hat JBoss Enterprise Application Platform Expansion Pack: affected versions not specified
  • Red Hat Process Automation: version 7.0 only
  • Red Hat Single Sign-On: version 7.0 only
  • Red Hat Undertow: affected versions not specified

Published 2025-09-02. Last modified 2026-10-06.