logo

Internet-wide Vulnerability Enables Giant DDoS Attacks

ID: e6a1c6b7-e83c-5c20-ba6d-5d9a99cf71a7

STIX ID: report--e6a1c6b7-e83c-5c20-ba6d-5d9a99cf71a7

Feed Name: Dark Reading

Threat Score
72/100

Date Published: 2025-08-18

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

Researchers disclosed "MadeYouReset," an HTTP/2 protocol vulnerability that lets attackers trigger server-initiated stream resets (via invalid control frames) to evade stream limits and mount massive DDoS campaigns; it is tracked as CVE-2025-8671 and affects multiple implementations (Netty, F5 BIG-IP, Apache Tomcat, h2o, Jetty) with coordinated disclosure and partial mitigation efforts underway.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.