Versions of amphp/http-server prior to 3.4.4 for the 3.x release branch and prior to 2.1.10 for the 2.x release branch are vulnerable to the HTTP/2 "MadeYouReset" DoS attack described by CVE-2025-8671 and https://kb.cert.org/vuls/id/767506.
In versions 3.4.4 and 2.1.10, stream reset protection has been refactored to account for the number of reset streams within a sliding time window.
Note that your application must expose HTTP/2 connections directly to be affected by this vulnerability. Servers behind a proxy using HTTP/1.x such as nginx are not affected.
Original security advisory
Dear amphp Security Team,
We are writing to responsibly disclose a newly identified vulnerability in HTTP/2 with severe DDoS effects. This vulnerability introduces a novel method of exploitation against HTTP/2 server implementations — including the latest version of amphp http-server.
This vulnerability affects recent versions of several major servers and implementations, as this is a logical protocol-level vulnerability, not a flaw in a specific implementation.
We are security researchers from Tel Aviv University working on the resilience of Internet protocols. Our team has prior experience discovering logical vulnerabilities in core internet protocols, several of which have received CVEs.
We are committed to following a coordinated disclosure process and ensuring that vendors have sufficient time to patch before any public presentation or publication.
Disclosure & Coordination Timeline
We propose a standard embargo period of three months, during which no party shall publicly disclose the vulnerability details or release a patch. Concurrently, we are preparing an academic paper for submission to a top security conference, in alignment with the embargo period.
Next Steps
As this vulnerability affects multiple vendors and could have a wide impact, we suggest establishing a secure channel for sharing further details.
Upon confirmation of the embargo process, we will provide full technical details and a proof of concept code.
Best regards,
Gal Bar Nahum, Anat Bremler-Barr, Yaniv Harel
Tel Aviv University
Versions of
amphp/http-serverprior to3.4.4for the 3.x release branch and prior to2.1.10for the 2.x release branch are vulnerable to the HTTP/2 "MadeYouReset" DoS attack described by CVE-2025-8671 and https://kb.cert.org/vuls/id/767506.In versions
3.4.4and2.1.10, stream reset protection has been refactored to account for the number of reset streams within a sliding time window.Note that your application must expose HTTP/2 connections directly to be affected by this vulnerability. Servers behind a proxy using HTTP/1.x such as nginx are not affected.
Original security advisory
Dear amphp Security Team,
We are writing to responsibly disclose a newly identified vulnerability in HTTP/2 with severe DDoS effects. This vulnerability introduces a novel method of exploitation against HTTP/2 server implementations — including the latest version of amphp http-server.
This vulnerability affects recent versions of several major servers and implementations, as this is a logical protocol-level vulnerability, not a flaw in a specific implementation.
We are security researchers from Tel Aviv University working on the resilience of Internet protocols. Our team has prior experience discovering logical vulnerabilities in core internet protocols, several of which have received CVEs.
We are committed to following a coordinated disclosure process and ensuring that vendors have sufficient time to patch before any public presentation or publication.
Disclosure & Coordination Timeline
We propose a standard embargo period of three months, during which no party shall publicly disclose the vulnerability details or release a patch. Concurrently, we are preparing an academic paper for submission to a top security conference, in alignment with the embargo period.
Next Steps
As this vulnerability affects multiple vendors and could have a wide impact, we suggest establishing a secure channel for sharing further details.
Upon confirmation of the embargo process, we will provide full technical details and a proof of concept code.
Best regards,
Gal Bar Nahum, Anat Bremler-Barr, Yaniv Harel
Tel Aviv University