On August 13, 2025, the CERT Coordination Center updated its MadeYouReset vulnerability note. The note describes an HTTP/2 implementation flaw tracked as CVE-2025-8671. A client can trigger server-sent stream resets while backend work continues, which can exhaust server resources.
CERT/CC listed Cloudflare as notified on May 28, 2025, but marked its response status as unknown in the August update. The available record therefore did not support the original article’s claim that Cloudflare had deployed a specific global mitigation.
For CDN operators, the issue requires implementation-specific evidence. Confirm each provider’s exposure and mitigation instead of assuming that an HTTP/2 control or web application firewall rule addresses the affected server behavior.