Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

‘MadeYouReset’ HTTP2 Vulnerability Enables Massive DDoS Attacks

The new DDoS attack vector, which involves HTTP/2 implementation flaws, has been compared to Rapid Reset.

DDoS attack

Researchers have discovered another attack vector that can be exploited to launch massive distributed denial-of-service (DDoS) attacks.

The attack, dubbed MadeYouReset, is similar to Rapid Reset, which in 2023 was exploited in zero-day attacks that broke DDoS records in terms of requests per second (RPS). 

MadeYouReset, discovered by researchers at security firm Imperva and Tel Aviv University in Israel, leverages a design flaw in HTTP2 implementations.

“HTTP/2 introduced stream cancellation – the ability of both client and server to immediately close a stream at any time. However, after a stream is canceled, many implementations keep processing the request, compute the response, but don’t send it back to the client,” the CERT/CC at Carnegie Mellon University explained in an advisory. “This creates a mismatch between the amount of active streams from the HTTP/2 point of view, and the actual active HTTP requests the backend server is processing.”

“By opening streams and then rapidly triggering the server to reset them using malformed frames or flow control errors, an attacker can exploit a discrepancy created between HTTP/2 streams accounting and the servers active HTTP requests. Streams reset by the server are considered closed, even though backend processing continues. This allows a client to cause the server to handle an unbounded number of concurrent HTTP/2 requests on a single connection.” CERT/CC added.

An attacker can continually send reset requests to the targeted server, resulting in highly disruptive DDoS attacks.

Advertisement. Scroll to continue reading.

However, unlike in the case of Rapid Reset, the MadeYouReset method does not appear to have been exploited in the wild. 

The underlying vulnerability, tracked as CVE-2025-8671, has been found to impact projects and organizations such as AMPHP, Apache Tomcat, the Eclipse Foundation, F5, Fastly, gRPC, Mozilla, Netty, Suse Linux, Varnish Software, Wind River, and Zephyr Project.

Patches have already been released by Apache Tomcat developers, F5, Fastly, and Varnish. Others are still investigating the impact and extent of the flaw. Mozilla is working on patches for affected services and websites, but pointed out that software such as Firefox is not impacted. 

While the vulnerability has been assigned CVE-2025-8671, some of the impacted vendors have assigned their own CVE identifiers. 

Imperva pointed out that MadeYouReset blends with normal traffic, making it more difficult to detect. The company noted that the attack may bypass many existing defenses, but there are several mitigations and other solutions that can thwart attacks.

Related: New HTTP/2 DoS Attack Potentially More Severe Than Record-Breaking Rapid Reset

Related: DDoS Attacks Blocked by Cloudflare in 2025 Already Surpass 2024 Total

Related: Record-Breaking 7.3 Tbps DDoS Attack Targets Hosting Provider

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Organizations are investing heavily in third-party risk management, but breaches, delays, and blind spots continue to persist. Join this live webinar as we examine the gap between how organizations think their third-party risk programs are performing and what’s actually happening in practice.

Register

Explore how attackers are using AI to scale threats and how security teams can respond with AI-driven defenses. Protecting against unmonitored use of generative AI (Shadow AI) in business units and building and enforcing AI governance frameworks.

Register

People on the Move

Opal Security has appointed CPO, CTO, VP of Field Engineering, VP of Marketing, and Head of Product and Solutions Marketing.

The Department of the Air Force has appointed Ashley Devoto as Chief Information Officer.

Bartley Richardson has been named Chief AI and Autonomous Systems Officer at CrowdStrike.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.