CVE-2025-55163 - CVE House
Back to Database
Status published High CVE-2025-55163

Netty MadeYouReset HTTP/2 DDoS Vulnerability

Vulnerability Description

Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.124.Final and 4.2.4.Final, Netty is vulnerable to MadeYouReset DDoS. This is a logical vulnerability in the HTTP/2 protocol, that uses malformed HTTP/2 control frames in order to break the max concurrent streams limit - which results in resource exhaustion and distributed denial of service. This issue has been patched in versions 4.1.124.Final and 4.2.4.Final.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-55163

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

netty
Vulnerable Versions:
< 4.1.124.Final, < 4.2.4.Final

Timeline

Official Publish: August 13th, 2025
Last Modified: November 4th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)