{
  "threat_severity" : "Important",
  "public_date" : "2025-09-01T06:21:54Z",
  "bugzilla" : {
    "description" : "undertow: Undertow MadeYouReset HTTP/2 DDoS Vulnerability",
    "id" : "2392306",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2392306"
  },
  "cvss3" : {
    "cvss3_base_score" : "7.5",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
    "status" : "verified"
  },
  "cwe" : "CWE-770",
  "details" : [ "A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the \"MadeYouReset\" attack, allows malicious clients to induce excessive server workload by repeatedly causing server-side stream aborts. While not a protocol bug, this highlights a common implementation weakness that can be exploited to cause a denial of service (DoS).", "A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the \"MadeYouReset\" attack, allows malicious clients to induce excessive server workload by repeatedly causing server-side stream aborts. While not a protocol bug, this highlights a common implementation weakness that can be exploited to cause a denial of service (DoS)." ],
  "statement" : "This vulnerability is rated with an Important severity. It is simple to exploit because it does not require authentication and could result in a Denial of Service (DoS). While some DoS flaws are classified as Moderate, “MadeYouReset” is Important because of the limited barriers (no specialized tooling or advanced scripting) to exploitation, which directly impacts service availability. The vulnerability arises from an implementation weakness in HTTP/2 stream reset handling — malformed client requests can trigger server-side resets without incrementing abuse counters, allowing an attacker to bypass built-in request throttling and overhead limits. Since these resets consume CPU and memory resources and can be generated at scale over a single TCP/TLS connection, a remote attacker could exhaust server capacity quickly, impacting all legitimate clients.",
  "affected_release" : [ {
    "product_name" : "Red Hat build of Apache Camel 4.14.2 for Spring Boot 3.5.8",
    "release_date" : "2025-12-11T00:00:00Z",
    "advisory" : "RHSA-2025:23143",
    "cpe" : "cpe:/a:redhat:apache_camel_spring_boot:4.14",
    "package" : "undertow-core"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.4",
    "release_date" : "2026-03-18T00:00:00Z",
    "advisory" : "RHSA-2026:4924",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.4",
    "package" : "undertow-core"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7",
    "release_date" : "2026-03-18T00:00:00Z",
    "advisory" : "RHSA-2026:4915",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform_els:7.4::el7",
    "package" : "eap7-undertow-0:2.2.39-1.Final_redhat_00001.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7",
    "release_date" : "2026-03-18T00:00:00Z",
    "advisory" : "RHSA-2026:4915",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform_els:7.4::el7",
    "package" : "eap7-wildfly-0:7.4.24-4.GA_redhat_00002.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 8",
    "release_date" : "2026-03-18T00:00:00Z",
    "advisory" : "RHSA-2026:4916",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform_els:7.4::el8",
    "package" : "eap7-undertow-0:2.2.39-1.Final_redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 8",
    "release_date" : "2026-03-18T00:00:00Z",
    "advisory" : "RHSA-2026:4916",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform_els:7.4::el8",
    "package" : "eap7-wildfly-0:7.4.24-4.GA_redhat_00002.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 9",
    "release_date" : "2026-03-18T00:00:00Z",
    "advisory" : "RHSA-2026:4917",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform_els:7.4::el9",
    "package" : "eap7-undertow-0:2.2.39-1.Final_redhat_00001.1.el9eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 9",
    "release_date" : "2026-03-18T00:00:00Z",
    "advisory" : "RHSA-2026:4917",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform_els:7.4::el9",
    "package" : "eap7-wildfly-0:7.4.24-4.GA_redhat_00002.1.el9eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8.0",
    "release_date" : "2026-03-05T00:00:00Z",
    "advisory" : "RHSA-2026:3892",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8.0::el8",
    "package" : "undertow-core"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8",
    "release_date" : "2026-03-05T00:00:00Z",
    "advisory" : "RHSA-2026:3889",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8.0::el8",
    "package" : "eap8-bouncycastle-0:1.83.0-1.redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8",
    "release_date" : "2026-03-05T00:00:00Z",
    "advisory" : "RHSA-2026:3889",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8.0::el8",
    "package" : "eap8-guava-libraries-0:33.0.0-2.jre_redhat_00003.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8",
    "release_date" : "2026-03-05T00:00:00Z",
    "advisory" : "RHSA-2026:3889",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8.0::el8",
    "package" : "eap8-jaxb-0:4.0.6-1.redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8",
    "release_date" : "2026-03-05T00:00:00Z",
    "advisory" : "RHSA-2026:3889",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8.0::el8",
    "package" : "eap8-jcip-annotations-0:1.0.0-3.redhat_00009.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8",
    "release_date" : "2026-03-05T00:00:00Z",
    "advisory" : "RHSA-2026:3889",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8.0::el8",
    "package" : "eap8-slf4j-jboss-logmanager-0:2.0.2-1.Final_redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8",
    "release_date" : "2026-03-05T00:00:00Z",
    "advisory" : "RHSA-2026:3889",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8.0::el8",
    "package" : "eap8-undertow-0:2.3.23-1.SP3_redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9",
    "release_date" : "2026-03-05T00:00:00Z",
    "advisory" : "RHSA-2026:3891",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8.0::el9",
    "package" : "eap8-bouncycastle-0:1.83.0-1.redhat_00001.1.el9eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9",
    "release_date" : "2026-03-05T00:00:00Z",
    "advisory" : "RHSA-2026:3891",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8.0::el9",
    "package" : "eap8-guava-libraries-0:33.0.0-2.jre_redhat_00003.1.el9eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9",
    "release_date" : "2026-03-05T00:00:00Z",
    "advisory" : "RHSA-2026:3891",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8.0::el9",
    "package" : "eap8-jaxb-0:4.0.6-1.redhat_00001.1.el9eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9",
    "release_date" : "2026-03-05T00:00:00Z",
    "advisory" : "RHSA-2026:3891",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8.0::el9",
    "package" : "eap8-jcip-annotations-0:1.0.0-3.redhat_00009.1.el9eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9",
    "release_date" : "2026-03-05T00:00:00Z",
    "advisory" : "RHSA-2026:3891",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8.0::el9",
    "package" : "eap8-slf4j-jboss-logmanager-0:2.0.2-1.Final_redhat_00001.1.el9eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9",
    "release_date" : "2026-03-05T00:00:00Z",
    "advisory" : "RHSA-2026:3891",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8.0::el9",
    "package" : "eap8-undertow-0:2.3.23-1.SP3_redhat_00001.1.el9eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8.1",
    "release_date" : "2026-01-08T00:00:00Z",
    "advisory" : "RHSA-2026:0386",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8.0::el8",
    "package" : "undertow-core"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8",
    "release_date" : "2026-01-08T00:00:00Z",
    "advisory" : "RHSA-2026:0383",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8.1::el8",
    "package" : "eap8-apache-cxf-0:4.0.10-1.redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8",
    "release_date" : "2026-01-08T00:00:00Z",
    "advisory" : "RHSA-2026:0383",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8.1::el8",
    "package" : "eap8-bouncycastle-0:1.82.0-1.redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8",
    "release_date" : "2026-01-08T00:00:00Z",
    "advisory" : "RHSA-2026:0383",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8.1::el8",
    "package" : "eap8-eap-product-conf-parent-0:801.3.0-1.GA_redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8",
    "release_date" : "2026-01-08T00:00:00Z",
    "advisory" : "RHSA-2026:0383",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8.1::el8",
    "package" : "eap8-eventstream-0:1.0.1-3.redhat_00003.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8",
    "release_date" : "2026-01-08T00:00:00Z",
    "advisory" : "RHSA-2026:0383",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8.1::el8",
    "package" : "eap8-hibernate-0:6.6.36-1.Final_redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8",
    "release_date" : "2026-01-08T00:00:00Z",
    "advisory" : "RHSA-2026:0383",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8.1::el8",
    "package" : "eap8-jboss-el-api_5.0_spec-0:4.0.2-1.Final_redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8",
    "release_date" : "2026-01-08T00:00:00Z",
    "advisory" : "RHSA-2026:0383",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8.1::el8",
    "package" : "eap8-jboss-threads-0:2.5.0-1.redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8",
    "release_date" : "2026-01-08T00:00:00Z",
    "advisory" : "RHSA-2026:0383",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8.1::el8",
    "package" : "eap8-undertow-0:2.3.20-2.SP4_redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8",
    "release_date" : "2026-01-08T00:00:00Z",
    "advisory" : "RHSA-2026:0383",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8.1::el8",
    "package" : "eap8-wildfly-0:8.1.3-4.GA_redhat_00006.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8",
    "release_date" : "2026-01-08T00:00:00Z",
    "advisory" : "RHSA-2026:0383",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8.1::el8",
    "package" : "eap8-wildfly-clustering-0:5.0.12-1.Final_redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8",
    "release_date" : "2026-01-08T00:00:00Z",
    "advisory" : "RHSA-2026:0383",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8.1::el8",
    "package" : "eap8-wildfly-elytron-0:2.6.6-1.Final_redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8",
    "release_date" : "2026-01-08T00:00:00Z",
    "advisory" : "RHSA-2026:0383",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8.1::el8",
    "package" : "eap8-wildfly-javadocs-0:8.1.1-4.GA_redhat_00007.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9",
    "release_date" : "2026-01-08T00:00:00Z",
    "advisory" : "RHSA-2026:0384",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8.1::el9",
    "package" : "eap8-apache-cxf-0:4.0.10-1.redhat_00001.1.el9eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9",
    "release_date" : "2026-01-08T00:00:00Z",
    "advisory" : "RHSA-2026:0384",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8.1::el9",
    "package" : "eap8-bouncycastle-0:1.82.0-1.redhat_00001.1.el9eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9",
    "release_date" : "2026-01-08T00:00:00Z",
    "advisory" : "RHSA-2026:0384",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8.1::el9",
    "package" : "eap8-eap-product-conf-parent-0:801.3.0-1.GA_redhat_00001.1.el9eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9",
    "release_date" : "2026-01-08T00:00:00Z",
    "advisory" : "RHSA-2026:0384",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8.1::el9",
    "package" : "eap8-eventstream-0:1.0.1-3.redhat_00003.1.el9eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9",
    "release_date" : "2026-01-08T00:00:00Z",
    "advisory" : "RHSA-2026:0384",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8.1::el9",
    "package" : "eap8-hibernate-0:6.6.36-1.Final_redhat_00001.1.el9eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9",
    "release_date" : "2026-01-08T00:00:00Z",
    "advisory" : "RHSA-2026:0384",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8.1::el9",
    "package" : "eap8-jboss-el-api_5.0_spec-0:4.0.2-1.Final_redhat_00001.1.el9eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9",
    "release_date" : "2026-01-08T00:00:00Z",
    "advisory" : "RHSA-2026:0384",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8.1::el9",
    "package" : "eap8-jboss-threads-0:2.5.0-1.redhat_00001.1.el9eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9",
    "release_date" : "2026-01-08T00:00:00Z",
    "advisory" : "RHSA-2026:0384",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8.1::el9",
    "package" : "eap8-undertow-0:2.3.20-2.SP4_redhat_00001.1.el9eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9",
    "release_date" : "2026-01-08T00:00:00Z",
    "advisory" : "RHSA-2026:0384",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8.1::el9",
    "package" : "eap8-wildfly-0:8.1.3-4.GA_redhat_00006.1.el9eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9",
    "release_date" : "2026-01-08T00:00:00Z",
    "advisory" : "RHSA-2026:0384",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8.1::el9",
    "package" : "eap8-wildfly-clustering-0:5.0.12-1.Final_redhat_00001.1.el9eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9",
    "release_date" : "2026-01-08T00:00:00Z",
    "advisory" : "RHSA-2026:0384",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8.1::el9",
    "package" : "eap8-wildfly-elytron-0:2.6.6-1.Final_redhat_00001.1.el9eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9",
    "release_date" : "2026-01-08T00:00:00Z",
    "advisory" : "RHSA-2026:0384",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8.1::el9",
    "package" : "eap8-wildfly-javadocs-0:8.1.1-4.GA_redhat_00007.1.el9eap"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat build of Apache Camel - HawtIO 4",
    "fix_state" : "Not affected",
    "package_name" : "undertow-core",
    "cpe" : "cpe:/a:redhat:apache_camel_hawtio:4"
  }, {
    "product_name" : "Red Hat Data Grid 8",
    "fix_state" : "Will not fix",
    "package_name" : "undertow-core",
    "cpe" : "cpe:/a:redhat:jboss_data_grid:8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 10",
    "fix_state" : "Not affected",
    "package_name" : "moditect",
    "cpe" : "cpe:/o:redhat:enterprise_linux:10"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "fix_state" : "Not affected",
    "package_name" : "pki-core:10.6/resteasy",
    "cpe" : "cpe:/o:redhat:enterprise_linux:8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "fix_state" : "Not affected",
    "package_name" : "pki-deps:10.6/resteasy",
    "cpe" : "cpe:/o:redhat:enterprise_linux:8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "fix_state" : "Not affected",
    "package_name" : "resteasy",
    "cpe" : "cpe:/o:redhat:enterprise_linux:9"
  }, {
    "product_name" : "Red Hat Fuse 7",
    "fix_state" : "Will not fix",
    "package_name" : "undertow-core",
    "cpe" : "cpe:/a:redhat:jboss_fuse:7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8",
    "fix_state" : "Not affected",
    "package_name" : "org.jberet-jberet-parent",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8",
    "fix_state" : "Not affected",
    "package_name" : "org.jboss.eap-jboss-eap-xp",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform Expansion Pack",
    "fix_state" : "Affected",
    "package_name" : "org.jboss.eap-jboss-eap-xp",
    "cpe" : "cpe:/a:redhat:jbosseapxp"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform Expansion Pack",
    "fix_state" : "Not affected",
    "package_name" : "undertow-core",
    "cpe" : "cpe:/a:redhat:jbosseapxp"
  }, {
    "product_name" : "Red Hat Process Automation 7",
    "fix_state" : "Affected",
    "package_name" : "undertow-core",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_bpms_platform:7"
  }, {
    "product_name" : "Red Hat Single Sign-On 7",
    "fix_state" : "Will not fix",
    "package_name" : "undertow-core",
    "cpe" : "cpe:/a:redhat:red_hat_single_sign_on:7"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2025-9784\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-9784\nhttps://github.com/undertow-io/undertow/pull/1778\nhttps://github.com/undertow-io/undertow/releases/tag/2.2.38.Final\nhttps://issues.redhat.com/browse/UNDERTOW-2598\nhttps://kb.cert.org/vuls/id/767506" ],
  "name" : "CVE-2025-9784",
  "mitigation" : {
    "value" : "No mitigation is currently available that meets Red Hat Product Security’s standards for usability, deployment, applicability, or stability.",
    "lang" : "en:us"
  },
  "csaw" : false
}