Internet-wide Vulnerability Enables Giant DDoS Attacks
ID: e6a1c6b7-e83c-5c20-ba6d-5d9a99cf71a7
STIX ID: report--e6a1c6b7-e83c-5c20-ba6d-5d9a99cf71a7
Feed Name: Dark Reading
Threat Score
Researchers disclosed "MadeYouReset," an HTTP/2 protocol vulnerability that lets attackers trigger server-initiated stream resets (via invalid control frames) to evade stream limits and mount massive DDoS campaigns; it is tracked as CVE-2025-8671 and affects multiple implementations (Netty, F5 BIG-IP, Apache Tomcat, h2o, Jetty) with coordinated disclosure and partial mitigation efforts underway.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
