mediumCVSS 5.3Vulnerability

GHSA-8grv-jq2g-cfhw

Versions of `amphp/http-server` prior to `3.4.4` for the 3.x release branch and prior to `2.1.10` for the 2.x release branch are vulnerable to the HTTP/2 "MadeYouReset" DoS attack described by CVE-2025-8671 and https://kb.cert.org/vuls/id/767506. In versions `3.4.4` and `2.1.10`, stream reset protection has been refactored to account for the number of reset streams within a sliding time window. Note that your application must expose HTTP/2 connections directly to be affected by this vulnerability. Servers behind a proxy using HTTP/1.x such as nginx are not affected.

Properties

ghsa_id
GHSA-8grv-jq2g-cfhw
severity
medium
summary
amphp/http-server affected by HTTP/2 DDoS vulnerability
cvss_score
5.3
cve_id
GHSA-8grv-jq2g-cfhw
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
is_ghsa_only
true
ghsa_published
2026-02-10T00:25:41Z
source_url
https://github.com/advisories/GHSA-8grv-jq2g-cfhw
ghsa_updated
2026-02-10T11:47:11Z

Related Entities (3)

AFFECTS (1)

[Software]composer/amphp/http-server

HAS_WEAKNESS (1)

[Weakness]Uncontrolled Resource Consumption

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-8grv-jq2g-cfhw (CVSS 5.3) — Ninja Signal Threat Intelligence | Ninja Signal