Get real-time updates on Telegram
P4Verified
Undertow MadeYouReset HTTP/2 DDoS Vulnerability
CVE-2025-9784 affects io.undertow:undertow-core. CVSS base score 7.5 (HIGH, Vendor/CNA). EPSS 0.02325 (percentile 0.82905), scored 2026-10-04. Affected range: < 2.2.38.Final. Fixed version: 2.2.38.Final. Affected range: >= 2.3.0.Alpha1, < 2.3.20.Final. Fixed version: 2.3.20.Final.
- CVE
- CVE-2025-9784
- CWE
- CWE-404, CWE-770
- Product
- io.undertow:undertow-core
- CCR priority
- 30.6 /100 (P4)
- CVSS
- 7.5 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H · Vendor/CNA
- EPSS
- 0.02325 · percentile 0.82905 · 2026-10-04
- KEV
- no
Affected products
- cpe:2.3:a:redhat:build_of_apache_camel_for_spring_boot:-:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:fuse:7.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:jboss_enterprise_application_platform:8.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:jboss_enterprise_application_platform_expansion_pack:-:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:process_automation:7.0:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:single_sign-on:7.0:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:undertow:-:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:-:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
- io.undertow:undertow-core · < 2.2.38.Final · Fixed version: 2.2.38.Final
- io.undertow:undertow-core · >= 2.3.0.Alpha1, < 2.3.20.Final · Fixed version: 2.3.20.Final
Provenance
- NVD CVE API 2.0 · Source record · observed 2026-10-06 00:26:03.168174+00:00 UTC
- GitHub Advisory Database · Source record · observed 2026-10-06 01:14:31.382806+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2025-9784.html