Lune

S&P2026顶会

MadeYouReset: Exploiting HTTP/2 Server-Side Resets for Large-Scale DoS

Gal Bar Nahum, Anat Bremler Barr, Yaniv Harel

2026年份

摘要

We present MadeYouReset, a novel DoS vulnerability that exploits a fundamental design flaw in HTTP/2 servers. In this attack, malicious clients send specially crafted, invalid yet protocol-compliant control frames, which cause the server to issue RST_STREAM frames, thereby terminating (resetting) the stream from the protocol's perspective. In practice, these resets do not cancel the associated backend processing on the server. As a result, the attacker is able to circumvent the protocol-enforced concurrent stream limit, allowing unbounded in-flight requests and creating a potent vector for denial-of-service. We demonstrate that numerous HTTP/2 server implementations are vulnerable to MadeYouReset. We further show that it effectively bypasses current defenses designed for the Rapid Reset vulnerability, which involved client-initiated resets by explicitly sending RST_STREAM frames. Notably, Rapid Reset was published in 2023, while already under active exploitation, leading to large-scale service crashes. In this paper, we analyze the vulnerability's behavior and measure its impact and sensitivity to major parameters. We demonstrate that the potential damage from MadeYouReset is comparable to that of Rapid Reset. We explore mitigation strategies and detection techniques. As part of our responsible disclosure, MadeYouReset was assigned a general CVE (CVE-2025-8671). To date, six additional product-specific CVEs have been issued. Corresponding patches have been applied across major HTTP/2 servers and libraries, including: Netty, Jetty, Apache Tomcat, H2O, h2 (Rust), SwiftNIO (Apple's framework), Pingora (Cloudflare's framework), and others.

问问这篇 Paper

问问你的智能体。

Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。

可以从这些问题问起

智能体调用

Lunesearch_papers

在 Lune 里问

免费开始,无需绑卡

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖