MadeYouReset Disclosure Listed Cloudflare Status as Unknown
On August 13, 2025, the CERT Coordination Center updated its MadeYouReset vulnerability note. The note describes an HTTP/2 implementation flaw tracked as CVE-2025-8671. A client can trigger server-sent stream resets while backend work continues, which can exhaust server resources. CERT/CC listed Cloudflare as notified on May 28, 2025, but marked its response status as unknown in the August update. The available record therefore did not support the original article’s claim that Cloudflare had deployed a specific global mitigation. ...