MadeYouReset: Exploiting HTTP/2 Server-Side Resets for Large-Scale DoS
Gal Bar Nahum, Anat Bremler Barr, Yaniv Harel
Abstract
We present MadeYouReset, a novel DoS vulnerability that exploits a fundamental design flaw in HTTP/2 servers. In this attack, malicious clients send specially crafted, invalid yet protocol-compliant control frames, which cause the server to issue RST_STREAM frames, thereby terminating (resetting) the stream from the protocol's perspective. In practice, these resets do not cancel the associated backend processing on the server. As a result, the attacker is able to circumvent the protocol-enforced concurrent stream limit, allowing unbounded in-flight requests and creating a potent vector for denial-of-service. We demonstrate that numerous HTTP/2 server implementations are vulnerable to MadeYouReset. We further show that it effectively bypasses current defenses designed for the Rapid Reset vulnerability, which involved client-initiated resets by explicitly sending RST_STREAM frames. Notably, Rapid Reset was published in 2023, while already under active exploitation, leading to large-scale service crashes. In this paper, we analyze the vulnerability's behavior and measure its impact and sensitivity to major parameters. We demonstrate that the potential damage from MadeYouReset is comparable to that of Rapid Reset. We explore mitigation strategies and detection techniques. As part of our responsible disclosure, MadeYouReset was assigned a general CVE (CVE-2025-8671). To date, six additional product-specific CVEs have been issued. Corresponding patches have been applied across major HTTP/2 servers and libraries, including: Netty, Jetty, Apache Tomcat, H2O, h2 (Rust), SwiftNIO (Apple's framework), Pingora (Cloudflare's framework), and others.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Related papers
- FRAGJAM: DoS Attacks Using IP Reassembly CongestionYepeng Pan, Christian RossowUSENIX Security 2026
- FRAMESHIFTER: Security Implications of HTTP/2-to-HTTP/1 Conversion AnomaliesBahruz Jabiyev, Steven Sprecher, Anthony Gavazzi, Tommaso Innocenti et al.USENIX Security 2022
- CDN Judo: Breaking the CDN DoS Protection with ItselfRun Guo, Weizhong Li, Baojun Liu, Shuang Hao et al.NDSS 2020
- SPCA: Stream Parser Confusion Attack for Web Application Firewall Evasion in HTTP/2Kyungrok Choi, Woonghee Lee, Junbeom HurWWW 2026
- DNSBomb: A New Practical-and-Powerful Pulsing DoS Attack Exploiting DNS Queries-and-ResponsesXiang Li, Dashuai Wu, Haixin Duan, Qi LiS&P 2024 · 14 citations
