Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-55163

Опубликовано: 13 авг. 2025
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.124.Final and 4.2.4.Final, Netty is vulnerable to MadeYouReset DDoS. This is a logical vulnerability in the HTTP/2 protocol, that uses malformed HTTP/2 control frames in order to break the max concurrent streams limit - which results in resource exhaustion and distributed denial of service. This issue has been patched in versions 4.1.124.Final and 4.2.4.Final.

A flaw was found in Netty where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive server workload by repeatedly causing server-side stream aborts. While not a protocol bug, this highlights a common implementation weakness that can be exploited to cause a denial of service (DoS).

Отчет

This vulnerability is rated with an Important severity. It is simple to exploit because it does not require authentication and could result in a denial of service (DoS). While some DoS flaws are classified as Moderate, “MadeYouReset” is Important because of the limited barriers (no specialized tooling or advanced scripting) to exploitation, which directly impacts service availability. The vulnerability arises from an implementation weakness in HTTP/2 stream reset handling — malformed client requests can trigger server-side resets without incrementing abuse counters, allowing an attacker to bypass built-in request throttling and overhead limits. Since these resets consume CPU and memory resources and can be generated at scale over a single TCP/TLS connection, a remote attacker could exhaust server capacity quickly, impacting all legitimate clients.

Меры по смягчению последствий

No mitigation is currently available that meets Red Hat Product Security’s standards for usability, deployment, applicability, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
AMQ Clientsnetty-codec-http2Affected
Cryostat 4netty-codec-http2Affected
Logging Subsystem for Red Hat OpenShiftnetty-codec-http2Affected
OpenShift Serverlessopenshift-serverless-1/kn-ekb-dispatcher-rhel8Will not fix
OpenShift Serverlessopenshift-serverless-1/kn-ekb-kafka-controller-rhel8Will not fix
OpenShift Serverlessopenshift-serverless-1/kn-ekb-post-install-rhel8Will not fix
OpenShift Serverlessopenshift-serverless-1/kn-ekb-receiver-rhel8Will not fix
OpenShift Serverlessopenshift-serverless-1/kn-ekb-webhook-kafka-rhel8Will not fix
OpenShift Serverlessopenshift-serverless-1/kn-eventing-integrations-aws-ddb-streams-source-rhel8Will not fix
OpenShift Serverlessopenshift-serverless-1/kn-eventing-integrations-aws-s3-sink-rhel8Will not fix

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2388252netty: netty-codec-http2: Netty MadeYouReset HTTP/2 DDoS Vulnerability

EPSS

Процентиль: 17%
0.00055
Низкий

7.5 High

CVSS3

Связанные уязвимости

ubuntu
13 дней назад

Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.124.Final and 4.2.4.Final, Netty is vulnerable to MadeYouReset DDoS. This is a logical vulnerability in the HTTP/2 protocol, that uses malformed HTTP/2 control frames in order to break the max concurrent streams limit - which results in resource exhaustion and distributed denial of service. This issue has been patched in versions 4.1.124.Final and 4.2.4.Final.

nvd
15 дней назад

Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.124.Final and 4.2.4.Final, Netty is vulnerable to MadeYouReset DDoS. This is a logical vulnerability in the HTTP/2 protocol, that uses malformed HTTP/2 control frames in order to break the max concurrent streams limit - which results in resource exhaustion and distributed denial of service. This issue has been patched in versions 4.1.124.Final and 4.2.4.Final.

debian
15 дней назад

Netty is an asynchronous, event-driven network application framework. ...

github
15 дней назад

Netty affected by MadeYouReset HTTP/2 DDoS vulnerability

EPSS

Процентиль: 17%
0.00055
Низкий

7.5 High

CVSS3