Risky Bulletin Newsletter
August 15, 2025
Risky Bulletin: MadeYouReset vulnerability enables unlimited HTTP/2 DDoS attacks
Presented by
News Editor
A new vulnerability in the HTTP/2 protocol can allow threat actors to launch nearly unlimited DDoS attacks to exhaust memory and crash servers.
The new attack is named MadeYouReset, was discovered by researchers at Deepness Lab, and is a variation of a previous attack known as HTTP/2 Rapid Reset.
The Rapid Reset attack was discovered in October 2023 after it was used to launch some of the largest DDoS attacks seen that year (Google, Amazon, and Cloudflare).