CVE-2025-8671 - CVE House
Back to Database
Status published Unknown CVE-2025-8671

CVE-2025-8671

Vulnerability Description

A mismatch caused by client-triggered server-sent stream resets between HTTP/2 specifications and the internal architectures of some HTTP/2 implementations may result in excessive server resource consumption leading to denial-of-service (DoS). By opening streams and then rapidly triggering the server to reset them—using malformed frames or flow control errors—an attacker can exploit incorrect stream accounting. Streams reset by the server are considered closed at the protocol level, even though backend processing continues. This allows a client to cause the server to handle an unbounded number of concurrent streams on a single connection. This CVE will be updated as affected product details are released.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-8671

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Enterprise Module for Development Tools, Enterprise High Performance Computing (HPC), Varnish Enterprise, Varnish Cache, H20, Linux, Enterprise Desktop, Enterprise High Performance Computing, Enterprise Module for Dev Tools, Enterprise Module for Package Hub, Enterprise Server, Enterprise Server for SAP Applications, SUSE Manager Server, SUSE Manager Server LTS, SUSE Manager Proxy, SUSE Manager Retail Branch Server, openSUSE Leap
Vulnerable Versions:
15 SP2, 15, 6.0.x, 6.0LTS, 5.x, 579ecfa, LTS22, 15 SP6, 15 SP3, 15 SP5, 12 SP5, 4.3, 15.6

Timeline

Official Publish: August 13th, 2025
Last Modified: November 4th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.