logo

MadeYouReset: An HTTP/2 vulnerability thwarted by Rapid Reset mitigations

ID: cb7502e6-8355-5efa-9b74-6d8fd906ae7b

STIX ID: report--cb7502e6-8355-5efa-9b74-6d8fd906ae7b

Feed Name: Cloudflare Blog

Threat Score
30/100

Date Published: 2025-08-14

Date Updated: 2026-04-27

Author: Alex Forster

...
...

Cloudflare details the MadeYouReset (CVE-2025-8671) HTTP/2 denial-of-service vulnerability disclosed by Tel Aviv University researchers, explaining that abusing server-sent RST_STREAMs can exhaust server resources. The blog notes the issue impacts a limited set of unpatched HTTP/2 implementations, highlights prior related Rapid Reset mitigations, confirms Cloudflare is not vulnerable, and advises updating affected h2 library versions and implementing RFC 9113 mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.