Resource exhaustion in h2o - CVE-2025-8671
Published: August 13, 2025 / Updated: September 12, 2025
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources when handling HTTP/2 requests. A remote attacker can send specially crafted HTTP requests to the affected server and consume its all available memory, leading to denial of service.
Affected software
Debian Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
Basesystem Module
openEuler
Ubuntu
Fedora
lighttpd-debugsource
lighttpd-mod_authn_gssapi
lighttpd-mod_authn_mysql
lighttpd-mod_authn_pam
lighttpd-mod_mysql_vhost
lighttpd-filesystem
lighttpd-fastcgi
lighttpd-debuginfo
lighttpd
lighttpd-mod_vhostdb_pgsql
lighttpd-mod_vhostdb_mysql
lighttpd-mod_webdav
lighttpd-mod_authn_sasl
lighttpd-mod_vhostdb_ldap
lighttpd-mod_vhostdb_dbi
lighttpd-mod_openssl
lighttpd-mod_nss
lighttpd-mod_maxminddb
lighttpd-mod_magnet
lighttpd-mod_gnutls
lighttpd-mod_deflate
lighttpd-mod_authn_ldap
lighttpd-mod_authn_dbi
dnsdist (Ubuntu package)
dnsdist-debugsource
dnsdist-debuginfo
dnsdist
varnish-debuginfo
varnish-devel
varnish
varnish-debugsource
varnish-help
varnish (Debian package)
How to mitigate CVE-2025-8671
lighttpd-mod_authn_gssapi - addressed in versions 1.4.67-2, 1.4.72-2
lighttpd-mod_authn_mysql - update to 1.4.67-2
lighttpd-mod_authn_pam - addressed in versions 1.4.67-2, 1.4.72-2
lighttpd-mod_mysql_vhost - update to 1.4.67-2
lighttpd-filesystem - addressed in versions 1.4.67-2, 1.4.72-2
lighttpd-fastcgi - addressed in versions 1.4.67-2, 1.4.72-2
lighttpd-debuginfo - addressed in versions 1.4.67-2, 1.4.72-2
lighttpd - addressed in versions 1.4.67-2, 1.4.72-2
lighttpd-mod_vhostdb_pgsql - update to 1.4.72-2
lighttpd-mod_vhostdb_mysql - update to 1.4.72-2
lighttpd-mod_webdav - update to 1.4.72-2
lighttpd-mod_authn_sasl - update to 1.4.72-2
lighttpd-mod_vhostdb_ldap - update to 1.4.72-2
lighttpd-mod_vhostdb_dbi - update to 1.4.72-2
lighttpd-mod_openssl - update to 1.4.72-2
lighttpd-mod_nss - update to 1.4.72-2
lighttpd-mod_maxminddb - update to 1.4.72-2
lighttpd-mod_magnet - update to 1.4.72-2
lighttpd-mod_gnutls - update to 1.4.72-2
lighttpd-mod_deflate - update to 1.4.72-2
lighttpd-mod_authn_ldap - update to 1.4.72-2
lighttpd-mod_authn_dbi - update to 1.4.72-2
dnsdist (Ubuntu package) - addressed in versions 1.6.1-1ubuntu0.1~esm2, 1.8.3-2ubuntu0.1~esm1, 1.9.10-1ubuntu0.1
dnsdist-debugsource - update to 1.9.11-150700.3.6.1
dnsdist-debuginfo - update to 1.9.11-150700.3.6.1
dnsdist - update to 1.9.11-150700.3.6.1
varnish-debuginfo - update to 7.4.3-4
varnish-devel - update to 7.4.3-4
varnish - update to 7.4.3-4
varnish-debugsource - update to 7.4.3-4
varnish-help - update to 7.4.3-4
varnish (Debian package) - update to 7.7.0-3+deb13u1
varnish - update to 7.7.3-2.fc44
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- HTTP/2 Made You Reset Attack in h2o
- openEuler 24.03 LTS SP1 update for varnish
- openEuler 22.03 LTS SP4 update for varnish
- openEuler 22.03 LTS SP3 update for varnish
- openEuler 20.03 LTS SP4 update for varnish
- openEuler 24.03 LTS SP2 update for varnish
- openEuler 24.03 LTS SP2 update for lighttpd
- openEuler 24.03 LTS SP1 update for lighttpd
- openEuler 24.03 LTS update for varnish
- openEuler 24.03 LTS update for lighttpd
- openEuler 22.03 LTS SP4 update for lighttpd
- Fedora 44 update for varnish
- Ubuntu update for dnsdist
- openEuler 20.03 LTS SP4 update for lighttpd
- SUSE update for dnsdist
- Debian update for varnish