CVE-2025-9784 MadeYouReset HTTP/2 Vulnerability Test
Overview
This repository contains a simple and effective bash script to test for the CVE-2025-9784 vulnerability (known as the "MadeYouReset" HTTP/2 Denial of Service (DoS) attack) in Undertow HTTP/2 server implementations. The vulnerability allows attackers to induce excessive server workload by repeatedly causing server-side stream resets, leading to potential service disruption.
Features
- Detects if the target server supports HTTP/2 protocol.
- Measures baseline response times.
- Simulates rapid concurrent HTTP/2 stream creation to trigger resets.
- Analyzes server response behaviors under load.
- Provides a straightforward vulnerability assessment report.
Getting Started
Prerequisites
- Bash shell (Linux, macOS, WSL)
curl with HTTP/2 support
- Optional:
bc for floating-point arithmetic (most Linux distros include this by default)
Usage
- Clone or download this repository.
- Make the script executable:
chmod +x cve-2025-9784-test.sh
- Run the script against a target URL:
./cve-2025-9784-test.sh https://target-website.com
Output
- The script will output test progress and results, highlighting if any signs of potential vulnerability are detected.
- It checks the server's HTTP/2 capability, baseline response times, and simulates attack conditions.
- Final assessment notes if the server might be vulnerable based on response failure and delay patterns.
Important Notes
- Only test against systems you own or have explicit permission to assess.
- This script does not exploit the vulnerability but stresses the server to observe response anomalies.
- The vulnerability affects certain Undertow server implementations primarily found in Red Hat products and other Java-based servers.
- For more details on the vulnerability, visit the official advisory: Red Hat CVE-2025-9784
Contributing
Contributions, issues, and feature requests are welcome! Feel free to fork the repository and submit pull requests.
Disclaimer
This tool is for educational and authorized security testing purposes only. The author is not responsible for any misuse or damage caused by this script.