Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-8671

32
FAUCET Score

CVE-2025-8671 describes a denial-of-service vulnerability in HTTP/2 implementations stemming from a mismatch in how server-sent stream resets are handled. Attackers can exploit incorrect stream accounting by rapidly triggering server resets, leading to excessive resource consumption and DoS. While specific affected products are not yet listed, the vulnerability has a CVSS score of 7.5 (HIGH), indicating a network-based attack with low complexity and high availability impact. There is currently no public exploit code (Metasploit, Nuclei, ExploitDB), and it is not on the CISA KEV catalog, though it has garnered some community discussion and media attention.

Impacted Technologies

VendorProductVersion(s)CPE
SUSE LinuxEnterprise Desktop
>= 15 SP6, < 15 SP7CNA affected
SUSE LinuxEnterprise High Performance Computing (HPC)
>= 15, < 15 SP5CNA affected
SUSE LinuxEnterprise High Performance Computing
>= 15 SP3, < 15 SP7CNA affected
SUSE LinuxEnterprise Module For Dev Tools
>= 15 SP3, < 15 SP7CNA affected
SUSE LinuxEnterprise Module For Development Tools
>= 15 SP2, < 15-SP5CNA affected

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
3.51%
Probability of exploitation in next 30 days
EPSS Percentile
88.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0351 is in the 79th percentile among its peer group of 51,553 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Advisories (1)

redhatCVE-2025-8671

upstream:

Aug 13, 2025

References

deepness-lab.org / publications/madeyoureset
github.com / envoyproxy/envoy/issues/40739
github.com / Kong/kong/discussions/14731
github.com / varnish/hitch/issues/397
imperva.com / blog/madeyoureset-turning-http-2-server-against-itself
kb.cert.org / vuls/id/767506
openwall.com / lists/oss-security/2025/08/13/6
openwall.com / lists/oss-security/2025/09/18/1
galbarnahum.com / made-you-reset
github.com / h2o/h2o/commit/4729b661e3c6654198d2cc62997e1af58bef4b80
github.com / h2o/h2o/security/advisories/GHSA-mrjm-qq9m-9mjq
gitlab.isc.org / isc-projects/bind9/-/issues/5325
kb.cert.org / vuls/id/767506
support2.windriver.com / index.php
varnish-cache.org / security/VSV00017.html
fastlystatus.com / incident/377810
suse.com / support/kb/doc