https://seclists.org/oss-sec/2025/q3/131: HTTP/2 implementations avulnerable to "MadeYouset" DoS attack through HTTP/2 control frames
Published Aug 20, 2025
·Updated
Affected Software
1 affected component
Jetty jetty
Frequently Asked Questions
1
What is the severity of CVE-2025-5115?
CVE-2025-5115 is classified as a denial of service vulnerability.
2
How do I fix CVE-2025-5115?
To mitigate CVE-2025-5115, update Jetty to the latest version that addresses this vulnerability.
3
What is the impact of CVE-2025-5115 on Jetty?
CVE-2025-5115 allows an attacker to trigger a denial of service by sending malicious HTTP/2 control frames.
4
Is CVE-2025-5115 specific to certain versions of Jetty?
Yes, CVE-2025-5115 affects specific versions of Jetty that are vulnerable to the HTTP/2 MadeYouset DoS attack.
5
How can administrators protect their Jetty servers from CVE-2025-5115?
Administrators can protect Jetty servers by promptly applying patches and configuring server settings to mitigate the effects of the vulnerability.