Does CVE-2025-8671 (MadeYouReset) affect Apache HTTP Server 2.4.46+?

"Yoshihide Ito (Fujitsu) via users" <[email protected]> Thu, 12 Mar 2026 08:13:42 +0000
Newsgroups gmane.comp.apache.user
Message-ID <TY4PR01MB1459060FB3CEDB84A28DC5BE6EF44A@TY4PR01MB14590.jpnprd01.prod.outlook.com>
--_000_TY4PR01MB1459060FB3CEDB84A28DC5BE6EF44ATY4PR01MB14590jp_
Content-Type: text/plain; charset="iso-2022-jp"
Content-Transfer-Encoding: quoted-printable

Hello httpd users,

I would like to ask for clarification on whether Apache HTTP Server is
affected by the publicly disclosed HTTP/2 issue =1B$B!H=1B(BMadeYouReset=1B=
$B!I=1B(B
(CVE-2025-8671), and specifically whether httpd 2.4.46 or later should be
considered vulnerable. [1][2]

Our observations

- We are aware that Apache httpd's HTTP/2 support is implemented via
  mod_http2, and mod_http2 uses nghttp2 as its implementation base. [3]

- The nghttp2 project discussed this CVE and indicated that
  nghttp2 is not affected (see nghttp2 issue #2484). [4]

- However, we ran the detection tool published by one of the researchers
  (Gal Bar Nahum) against Apache HTTP Server 2.4.46 and 2.4.62 in =1B$B!H=
=1B(Bchecker mode=1B$B!I=1B(B.
  The tool reported that the =1B$B!H=1B(Boverflow-window=1B$B!I=1B(B primit=
ive appears to be
  applicable / detected for this target. [5]

Any pointers to prior discussion, documentation, or official statements
would be greatly appreciated.

Thank you for your time and guidance.

Best regards,
Yoshihide Ito


[1] CERT/CC VU#767506: https://kb.cert.org/vuls/id/767506
[2] NVD CVE-2025-8671: https://nvd.nist.gov/vuln/detail/CVE-2025-8671
[3] Apache httpd HTTP/2 guide (mod_http2 uses nghttp2): https://httpd.apach=
e.org/docs/2.4/howto/http2.html [httpd.apache.org]
[4] Tool by Gal Bar Nahum: https://github.com/galbarnahum/MadeYouReset
[5] nghttp2 issue #2484: https://github.com/nghttp2/nghttp2/issues/2484

--_000_TY4PR01MB1459060FB3CEDB84A28DC5BE6EF44ATY4PR01MB14590jp_
Content-Type: text/html; charset="iso-2022-jp"
Content-Transfer-Encoding: quoted-printable

<html xmlns:o=3D"urn:schemas-microsoft-com:office:office" xmlns:w=3D"urn:sc=
hemas-microsoft-com:office:word" xmlns:m=3D"http://schemas.microsoft.com/of=
fice/2004/12/omml" xmlns=3D"http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Diso-2022-=
jp">
<meta name=3D"Generator" content=3D"Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
	{font-family:"Cambria Math";
	panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
	{font-family:=1B$B^b%4%7%C%/=1B(B;
	panose-1:2 11 4 0 0 0 0 0 0 0;}
@font-face
	{font-family:"\@=1B$B^b%4%7%C%/=1B(B";
	panose-1:2 11 4 0 0 0 0 0 0 0;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0mm;
	font-size:10.5pt;
	font-family:=1B$B^b%4%7%C%/=1B(B;
	mso-ligatures:standardcontextual;}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:#467886;
	text-decoration:underline;}
span.17
	{mso-style-type:personal-compose;
	font-family:=1B$B^b%4%7%C%/=1B(B;
	color:windowtext;}
.MsoChpDefault
	{mso-style-type:export-only;}
/* Page Definitions */
@page WordSection1
	{size:612.0pt 792.0pt;
	margin:99.25pt 30.0mm 30.0mm 30.0mm;}
div.WordSection1
	{page:WordSection1;}
--></style>
</head>
<body lang=3D"JA" link=3D"#467886" vlink=3D"#96607D" style=3D"word-wrap:bre=
ak-word;text-justify-trim:punctuation">
<div class=3D"WordSection1">
<p class=3D"MsoNormal"><span lang=3D"EN-US">Hello httpd users,<o:p></o:p></=
span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US">I would like to ask for clarifi=
cation on whether Apache HTTP Server is<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US">affected by the publicly disclo=
sed HTTP/2 issue =1B$B!H=1B(BMadeYouReset=1B$B!I=1B(B<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US">(CVE-2025-8671), and specifical=
ly whether httpd 2.4.46 or later should be<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US">considered vulnerable. [1][2]<o=
:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US">Our observations<o:p></o:p></sp=
an></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US">- We are aware that Apache http=
d's HTTP/2 support is implemented via<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US">&nbsp; mod_http2, and mod_http2=
 uses nghttp2 as its implementation base. [3]<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US">- The nghttp2 project discussed=
 this CVE and indicated that<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US">&nbsp; nghttp2 is not affected =
(see nghttp2 issue #2484). [4]<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US">- However, we ran the detection=
 tool published by one of the researchers<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US">&nbsp; (Gal Bar Nahum) against =
Apache HTTP Server 2.4.46 and 2.4.62 in =1B$B!H=1B(Bchecker mode=1B$B!I=1B(=
B.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US">&nbsp; The tool reported that t=
he =1B$B!H=1B(Boverflow-window=1B$B!I=1B(B primitive appears to be<o:p></o:=
p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US">&nbsp; applicable / detected fo=
r this target. [5]<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US">Any pointers to prior discussio=
n, documentation, or official statements<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US">would be greatly appreciated.<o=
:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US">Thank you for your time and gui=
dance.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US">Best regards,<o:p></o:p></span>=
</p>
<p class=3D"MsoNormal"><span lang=3D"EN-US">Yoshihide Ito<o:p></o:p></span>=
</p>
<p class=3D"MsoNormal"><span lang=3D"EN-US"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US">[1] CERT/CC VU#767506: <a href=
=3D"https://kb.cert.org/vuls/id/767506">
https://kb.cert.org/vuls/id/767506</a><o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US">[2] NVD CVE-2025-8671: <a href=
=3D"https://nvd.nist.gov/vuln/detail/CVE-2025-8671">
https://nvd.nist.gov/vuln/detail/CVE-2025-8671</a><o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US">[3] Apache httpd HTTP/2 guide (=
mod_http2 uses nghttp2):
<a href=3D"https://httpd.apache.org/docs/2.4/howto/http2.html">https://http=
d.apache.org/docs/2.4/howto/http2.html</a> [httpd.apache.org]<o:p></o:p></s=
pan></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US">[4] Tool by Gal Bar Nahum: <a h=
ref=3D"https://github.com/galbarnahum/MadeYouReset">
https://github.com/galbarnahum/MadeYouReset</a><o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US">[5] nghttp2 issue #2484: <a hre=
f=3D"https://github.com/nghttp2/nghttp2/issues/2484">
https://github.com/nghttp2/nghttp2/issues/2484</a><o:p></o:p></span></p>
</div>
</body>
</html>

--_000_TY4PR01MB1459060FB3CEDB84A28DC5BE6EF44ATY4PR01MB14590jp_--