CVE-2025-8671 describes a denial-of-service vulnerability in HTTP/2 implementations stemming from a mismatch in how server-sent stream resets are handled. Attackers can exploit incorrect stream accounting by rapidly triggering server resets, leading to excessive resource consumption and DoS. While specific affected products are not yet listed, the vulnerability has a CVSS score of 7.5 (HIGH), indicating a network-based attack with low complexity and high availability impact. There is currently no public exploit code (Metasploit, Nuclei, ExploitDB), and it is not on the CISA KEV catalog, though it has garnered some community discussion and media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| SUSE Linux | Enterprise Desktop | >= 15 SP6, < 15 SP7CNA affected | |
| SUSE Linux | Enterprise High Performance Computing (HPC) | >= 15, < 15 SP5CNA affected | |
| SUSE Linux | Enterprise High Performance Computing | >= 15 SP3, < 15 SP7CNA affected | |
| SUSE Linux | Enterprise Module For Dev Tools | >= 15 SP3, < 15 SP7CNA affected | |
| SUSE Linux | Enterprise Module For Development Tools | >= 15 SP2, < 15-SP5CNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.