{"id":13147,"date":"2025-08-13T09:33:44","date_gmt":"2025-08-13T13:33:44","guid":{"rendered":"https:\/\/blog.litespeedtech.com\/?p=13147"},"modified":"2025-08-13T09:33:44","modified_gmt":"2025-08-13T13:33:44","slug":"litespeed-not-affected-by-madeyoureset","status":"publish","type":"post","link":"https:\/\/lswp.store\/index.php\/2025\/08\/13\/litespeed-not-affected-by-madeyoureset\/","title":{"rendered":"LiteSpeed Not Affected By MadeYouReset"},"content":{"rendered":"<p><img fetchpriority=\"high\" decoding=\"async\" class=\"aligncenter size-full wp-image-13149\" src=\"https:\/\/lswp.store\/wp-content\/uploads\/2025\/08\/madeyoureset.png\" alt=\"LiteSpeed Not Vulnerable to MadeYouReset HTTP\/2 Attack\" width=\"1000\" height=\"500\" srcset=\"https:\/\/lswp.store\/wp-content\/uploads\/2025\/08\/madeyoureset.png 1000w, https:\/\/lswp.store\/wp-content\/uploads\/2025\/08\/madeyoureset-300x150.png 300w, https:\/\/lswp.store\/wp-content\/uploads\/2025\/08\/madeyoureset-768x384.png 768w, https:\/\/lswp.store\/wp-content\/uploads\/2025\/08\/madeyoureset-600x300.png 600w\" sizes=\"(max-width: 1000px) 100vw, 1000px\" \/><\/p>\n<p>Here is what you need to know about LiteSpeed and the HTTP\/2 MadeYouReset vulnerability, specifically <a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-8671\">CVE-2025-8671<\/a>:<\/p>\n<ul>\n<li>MadeYouReset uses malformed HTTP\/2 control frames in order to break the maximum concurrent streams limit.<\/li>\n<li><strong>LiteSpeed server products (including LiteSpeed Web Server Enterprise, LiteSpeed Web ADC, and OpenLiteSpeed) are NOT vulnerable to MadeYouReset attacks<\/strong><\/li>\n<\/ul>\n<h2>What is MadeYouReset?<\/h2>\n<p>The MadeYouReset vulnerability was announced today as <a href=\"https:\/\/kb.cert.org\/vuls\/id\/767506\">Vulnerability Note #767506<\/a> published by the CERT Coordination Center.<\/p>\n<p>The note states:<\/p>\n<blockquote><p>By opening streams and then rapidly triggering the server to reset them using malformed frames or flow control errors, an attacker can exploit a discrepancy created between HTTP\/2 streams accounting and the servers active HTTP requests. Streams reset by the server are considered closed, even though backend processing continues. This allows a client to cause the server to handle an unbounded number of concurrent HTTP\/2 requests on a single connection.<\/p><\/blockquote>\n<h2>How are LiteSpeed Users Protected?<\/h2>\n<p>We simulated a MadeYouReset attack, and our LiteSpeed servers quickly blocked it due to the aggressiveness of the HTTP\/2 behavior. Before blocking the client, LiteSpeed\u2019s memory usage was not affected. This is mainly because of LiteSpeed\u2019s efficient stream life cycle and memory management. Resources are promptly released when streams are reset, even in cases where a quick blocking is not triggered.<\/p>\n<p>We are confident that MadeYouReset attacks cannot cause any trouble with LiteSpeed\u2019s HTTP\/2 implementation.<\/p>\n<p>If you are using LiteSpeed Web Server Enterprise, LiteSpeed Web ADC, or OpenLiteSpeed, there is nothing you need to do. You are already immune to this attack.<\/p>\n<ul>\n<li>Learn more about the HTTP\/2 MadeYouReset vulnerability at <a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-8671\">cve.org<\/a><\/li>\n<li><a href=\"https:\/\/litespeedtech.com\/products\/litespeed-web-server\/lsws-pricing\">Get LiteSpeed Web Server<\/a><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Here is what you need to know about LiteSpeed and the HTTP\/2 MadeYouReset vulnerability, specifically CVE-2025-8671: MadeYouReset uses malformed HTTP\/2 control frames in order to break the maximum concurrent streams limit. LiteSpeed server products (including LiteSpeed Web Server Enterprise, LiteSpeed Web ADC, and OpenLiteSpeed) are NOT vulnerable to MadeYouReset attacks What is MadeYouReset? The MadeYouReset [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":13149,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[23],"tags":[174],"class_list":["post-13147","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-madeyoureset"],"jetpack_featured_media_url":"https:\/\/lswp.store\/wp-content\/uploads\/2025\/08\/madeyoureset.png","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/posts\/13147","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/comments?post=13147"}],"version-history":[{"count":0,"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/posts\/13147\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/media\/13149"}],"wp:attachment":[{"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/media?parent=13147"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/categories?post=13147"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/tags?post=13147"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}