关键信息 漏洞名称 HTTP/2 MadeYouReset DDoS vulnerability 严重性 High (7.5 / 10) 影响版本 commits up to db98b59 修复版本 commits 4729b66 and above 描述 The HTTP/2 MadeYouReset DoS vulnerability is a logical vulnerability similar to the HTTP/2 Rapid Reset vulnerability that was identified and fixed in 2023. 影响 H2O is vulnerable to the HTTP/2 MadeYouReset attack. An attacker might be able to consume more than adequate amount of processing power of h2o and the backend servers by mounting the attack. 修复措施 All commits up to db98b59 are vulnerable. The vulnerability is fixed by commit 579ecfa. Users are advised to upgrade to commit 4729b66 or above that incorporates this fix. 参考资料 VU#767506 - kb.cert.org CVSS v3 基本指标 Attack vector: Network Attack complexity: Low Privileges required: None User interaction: None Scope: Unchanged Confidentiality: None Integrity: None Availability: High CVE ID CVE-2025-8671 弱点 No CWEs 报告者 galbaranahum AnatBB