Metrics
Affected Vendors & Products
Sat, 16 Aug 2025 00:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
| |
Metrics |
threat_severity
|
cvssV3_1
|
Thu, 14 Aug 2025 06:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Netty
Netty netty |
|
Vendors & Products |
Netty
Netty netty |
Wed, 13 Aug 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 13 Aug 2025 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.124.Final and 4.2.4.Final, Netty is vulnerable to MadeYouReset DDoS. This is a logical vulnerability in the HTTP/2 protocol, that uses malformed HTTP/2 control frames in order to break the max concurrent streams limit - which results in resource exhaustion and distributed denial of service. This issue has been patched in versions 4.1.124.Final and 4.2.4.Final. | |
Title | Netty MadeYouReset HTTP/2 DDoS Vulnerability | |
Weaknesses | CWE-770 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-08-13T14:37:20.727Z
Reserved: 2025-08-07T18:27:23.307Z
Link: CVE-2025-55163

Updated: 2025-08-13T14:37:10.688Z

Status : Awaiting Analysis
Published: 2025-08-13T15:15:39.390
Modified: 2025-08-13T17:33:46.673
Link: CVE-2025-55163
