Website Security & Threat Management
MadeYouReset: An HTTP/2 vulnerability thwarted by Rapid Reset mitigations

MadeYouReset: An HTTP/2 vulnerability thwarted by Rapid Reset mitigations

8/15/2025 · Alex Forster, Noah Maxwell Kennedy, Lucas Pardue, Evan Rittenhouse

What this post added

This post details the MadeYouReset (CVE-2025-8671) HTTP/2 vulnerability, which exploits server-sent stream resets. It explains how Cloudflare's existing mitigations for Rapid Reset and general HTTP/2 RFC 9113 compliance provide protection against this new vulnerability. It also notes that the Rust-language h2 library used by Cloudflare's Pingora framework was potentially susceptible in versions prior to 0.4.11, and advises users to update.

Read the original post ↗