Close Menu
    DevStackTipsDevStackTips
    • Home
    • News & Updates
      1. Tech & Work
      2. View All

      10 Ways Node.js Development Boosts AI & Real-Time Data (2025-2026 Edition)

      August 18, 2025

      Looking to Outsource React.js Development? Here’s What Top Agencies Are Doing Right

      August 18, 2025

      Beyond The Hype: What AI Can Really Do For Product Design

      August 18, 2025

      BrowserStack launches Chrome extension that bundles 10+ manual web testing tools

      August 18, 2025

      How much RAM does your Linux PC really need in 2025?

      August 19, 2025

      Have solar at home? Supercharge that investment with this other crucial component

      August 19, 2025

      I replaced my MacBook charger with this compact wall unit – and wish I’d done it sooner

      August 19, 2025

      5 reasons to switch to an immutable Linux distro today – and which to try first

      August 19, 2025
    • Development
      1. Algorithms & Data Structures
      2. Artificial Intelligence
      3. Back-End Development
      4. Databases
      5. Front-End Development
      6. Libraries & Frameworks
      7. Machine Learning
      8. Security
      9. Software Engineering
      10. Tools & IDEs
      11. Web Design
      12. Web Development
      13. Web Security
      14. Programming Languages
        • PHP
        • JavaScript
      Featured

      Sentry Adds Logs Support for Laravel Apps

      August 19, 2025
      Recent

      Sentry Adds Logs Support for Laravel Apps

      August 19, 2025

      Efficient Context Management with Laravel’s Remember Functions

      August 19, 2025

      Laravel Devtoolbox: Your Swiss Army Knife Artisan CLI

      August 19, 2025
    • Operating Systems
      1. Windows
      2. Linux
      3. macOS
      Featured

      From plateau predictions to buggy rollouts — Bill Gates’ GPT-5 skepticism looks strangely accurate

      August 18, 2025
      Recent

      From plateau predictions to buggy rollouts — Bill Gates’ GPT-5 skepticism looks strangely accurate

      August 18, 2025

      We gave OpenAI’s open-source AI a kid’s test — here’s what happened

      August 18, 2025

      With GTA 6, next-gen exclusives, and a console comeback on the horizon, Xbox risks sitting on the sidelines — here’s why

      August 18, 2025
    • Learning Resources
      • Books
      • Cheatsheets
      • Tutorials & Guides
    Home»Development»New HTTP/2 DoS Vulnerability Prompts Vendor and Project Fixes

    New HTTP/2 DoS Vulnerability Prompts Vendor and Project Fixes

    August 18, 2025

    MadeYouReset HTTP/2 DoS vulnerability

    A new HTTP/2 denial of service (DoS) vulnerability that circumvents mitigations put in place after 2023’s “Rapid Reset” vulnerability is largely being addressed by affected vendors and projects, thanks to responsible disclosure by the researchers who discovered the flaw.

    The new HTTP/2 DoS vulnerability, CVE-2025-8671, was publicly disclosed by Tel Aviv University researchers on Aug. 13, but the researchers have apparently been working with vendors since May to mitigate the flaw.

    According to a Cloudflare blog post, the vulnerability exists only “in a limited number of unpatched HTTP/2 server implementations that do not sufficiently enforce restrictions on the number of times a client may send malformed frames.”

    New HTTP/2 DoS Vulnerability Dubbed ‘MadeYouReset’

    Gal Bar Nahum, who discovered the flaw along with fellow Tel Aviv University researchers Anat Bremler‑Barr and Yaniv Harel, said in a blog post that the flaw “lets an attacker create effectively unbounded concurrent work on servers by bypassing HTTP/2’s built-in concurrency limit – causing a denial of service condition.”

    It builds on the flaw behind “Rapid Reset,” Nahum said, “with a neat twist that slips past the common mitigation.”

    2023’s Rapid Reset took advantage of HTTP/2’s request cancellation feature by opening streams and immediately canceling them using RST_STREAM so they didn’t count toward the MAX_CONCURRENT_STREAMS limit, which by default limits the number of active streams a client can have to 100.

    “The mitigation to Rapid Reset that was used by almost all affected implementations was very straightforward – limit the number of streams a client can cancel,” Nahum said.

    The researchers found a way around that limit by essentially making the server cancel the request instead of the client, an exploit they’ve dubbed “MadeYouReset.”

    “By crafting certain invalid control frames or violating protocol sequencing at just the right moment, we can make the server send RST_STREAM for a stream that already carried a valid request,” Nahum wrote.

    The researchers found six such primitives – which exploit WINDOW_UPDATE, PRIORITY, HEADERS and DATA frames – that were covered in a separate technical post.

    Vendors Respond to MadeYouReset HTTP/2 Vulnerability

    Cloudflare and Akamai said their implementations of HTTP/2 are not vulnerable to CVE-2025-8671, which is classified as an Improper Resource Shutdown or Release vulnerability (CWE-404).

    The Carnegie Mellon CERT Coordination Center listed a dozen vendors and projects that were affected by the flaw, some with differing CVEs, CWEs and severity ratings. Most of the affected vendors and projects appear to have issued fixes or mitigations, among them Apache Tomcat, F5, Fastly, h2o, Netty and IBM WebSphere Application Server Liberty.

    News of the MadeYouReset flaw also comes as PortSwigger released research detailing major security flaws in HTTP/1.1.

    Source: Read More

    Facebook Twitter Reddit Email Copy Link
    Previous ArticleWhat I learned from Inspired
    Next Article Noodlophile Malware Campaign Expands Global Reach with Copyright Phishing Lures

    Related Posts

    Development

    Sentry Adds Logs Support for Laravel Apps

    August 19, 2025
    Development

    Efficient Context Management with Laravel’s Remember Functions

    August 19, 2025
    Leave A Reply Cancel Reply

    For security, use of Google's reCAPTCHA service is required which is subject to the Google Privacy Policy and Terms of Use.

    Continue Reading

    CVE-2025-38155 – “Qualcomm Atheros mt76 Wireless Null Pointer Dereference Vulnerability”

    Common Vulnerabilities and Exposures (CVEs)

    I switched to a Hall Effect keyboard to see if magnets make all the difference, and I have to admit — I’m impressed

    News & Updates

    CVE-2025-49848 – Apache PRJ File Out-of-bounds Write Vulnerability

    Common Vulnerabilities and Exposures (CVEs)

    Microsoft fixes Windows Classic Outlook CAA2000B and 4usqa sign-in errors

    Operating Systems

    Highlights

    News & Updates

    I played Gears of War: Reloaded on the ROG Xbox Ally X, and it’s a fantastic experience that blew me away

    June 10, 2025

    I played Gears of War: Reloaded on the ROG Xbox Ally X after the Xbox…

    CVE-2025-3221 – IBM InfoSphere Information Server Denial of Service Vulnerability

    June 21, 2025

    The secret to getting repeat work as a freelancer

    July 31, 2025

    IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR) 2025

    June 4, 2025
    © DevStackTips 2025. All rights reserved.
    • Contact
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.