CVE-2025-9784: Red Hat Build Of Apache Camel For Spring Boot
High severity, CVSS 7.5. EPSS: 2.3% chance of exploitation in the next 30 days.
A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive server workload by repeatedly causing server-side stream aborts. While not a protocol bug, this highlights a common implementation weakness that can be exploited to cause a denial of service (DoS).
Affected products
- Red Hat Build Of Apache Camel For Spring Boot: affected versions not specified
- Red Hat Enterprise Linux: version 8.0 only; version 9.0 only
- Red Hat Fuse: version 7.0.0 only
- Red Hat JBoss Enterprise Application Platform: version 7.0.0 only; version 8.0.0 only
- Red Hat JBoss Enterprise Application Platform Expansion Pack: affected versions not specified
- Red Hat Process Automation: version 7.0 only
- Red Hat Single Sign-On: version 7.0 only
- Red Hat Undertow: affected versions not specified
Published 2025-09-02. Last modified 2026-10-06.