A mismatch caused by client-triggered server-sent stream resets between HTTP/2 specifications and the internal architectures of some HTTP/2 implementations may result in excessive server resource consumption leading to denial-of-service (DoS). By opening streams and then rapidly triggering the server to reset them—using malformed frames or flow control errors—an attacker can exploit incorrect stream accounting. Streams reset by the server are considered closed at the protocol level, even though backend processing continues. This allows a client to cause the server to handle an unbounded number of concurrent streams on a single connection. This CVE will be updated as affected product details are released.
History

Sun, 17 Aug 2025 15:30:00 +0000


Thu, 14 Aug 2025 06:30:00 +0000


Wed, 13 Aug 2025 20:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-404
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 13 Aug 2025 19:30:00 +0000

Type Values Removed Values Added
References

Wed, 13 Aug 2025 16:00:00 +0000

Type Values Removed Values Added
References

Wed, 13 Aug 2025 15:45:00 +0000

Type Values Removed Values Added
References

Wed, 13 Aug 2025 14:30:00 +0000

Type Values Removed Values Added
References

Wed, 13 Aug 2025 14:15:00 +0000


Wed, 13 Aug 2025 14:00:00 +0000

Type Values Removed Values Added
References

Wed, 13 Aug 2025 13:45:00 +0000

Type Values Removed Values Added
References

Wed, 13 Aug 2025 13:30:00 +0000


Wed, 13 Aug 2025 12:30:00 +0000

Type Values Removed Values Added
Description A mismatch caused by client-triggered server-sent stream resets between HTTP/2 specifications and the internal architectures of some HTTP/2 implementations may result in excessive server resource consumption leading to denial-of-service (DoS). By opening streams and then rapidly triggering the server to reset them—using malformed frames or flow control errors—an attacker can exploit incorrect stream accounting. Streams reset by the server are considered closed at the protocol level, even though backend processing continues. This allows a client to cause the server to handle an unbounded number of concurrent streams on a single connection. This CVE will be updated as affected product details are released.
Title CVE-2025-8671
References

cve-icon MITRE

Status: PUBLISHED

Assigner: certcc

Published: 2025-08-13T12:03:37.167Z

Updated: 2025-08-17T14:26:49.121Z

Reserved: 2025-08-06T11:52:46.667Z

Link: CVE-2025-8671

cve-icon Vulnrichment

Updated: 2025-08-17T14:26:49.121Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-08-13T13:15:34.790

Modified: 2025-08-17T15:15:25.687

Link: CVE-2025-8671

cve-icon Redhat

Severity :

Publid Date: 2025-08-13T12:03:37Z

Links: CVE-2025-8671 - Bugzilla