A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive server workload by repeatedly causing server-side stream aborts. While not a protocol bug, this highlights a common implementation weakness that can be exploited to cause a denial of service (DoS).
Update io.undertow:undertow-core to 2.2.38.Final; io.undertow:undertow-core to 2.3.20.Final if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanUndertow MadeYouReset HTTP/2 DDoS Vulnerability affects io.undertow:undertow-core (maven), io.undertow:undertow-core (maven). Severity is high. A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive server workload by repeatedly causing server-side stream aborts. While not a protocol bug, this highlights a common implementation weakness that can be exploited to cause a denial of service (DoS).
AI coding agents often install or upgrade packages automatically in maven. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| io.undertow:undertow-coremaven |
A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive server workload by repeatedly causing server-side stream aborts. While not a protocol bug, this highlights a common implementation weakness that can be exploited to cause a denial of service (DoS).
Update io.undertow:undertow-core to 2.2.38.Final; io.undertow:undertow-core to 2.3.20.Final if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanUndertow MadeYouReset HTTP/2 DDoS Vulnerability affects io.undertow:undertow-core (maven), io.undertow:undertow-core (maven). Severity is high. A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive server workload by repeatedly causing server-side stream aborts. While not a protocol bug, this highlights a common implementation weakness that can be exploited to cause a denial of service (DoS).
AI coding agents often install or upgrade packages automatically in maven. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| io.undertow:undertow-coremaven |
| <2.2.38.Final |
| 2.2.38.Final |
| io.undertow:undertow-coremaven | >=2.3.0.Alpha1,<2.3.20.Final | 2.3.20.Final |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| <2.2.38.Final |
| 2.2.38.Final |
| io.undertow:undertow-coremaven | >=2.3.0.Alpha1,<2.3.20.Final | 2.3.20.Final |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard