Red Hat Security Advisory: Red Hat Product OCP Tools 4.19 OpenShift Jenkins security update
Jenkins is a continuous integration server that monitors executions of repeated jobs, such as building a software project or jobs run by cron. Security Fix(es): * jenkins: HTTP/2 (including DNS over HTTPS) contains a design flaw and is vulnerable to "MadeYouReset" DoS attack through HTTP/2 control frames (CVE-2025-5115) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page listed in the References section.
AI Analysis
Technical Summary
The vulnerability identified as CVE-2025-5115 affects HTTP/2 implementations in Jetty components and Netty's HTTP/2 codec. It arises from an implementation weakness where malformed client requests cause server-side stream resets without triggering abuse counters, allowing attackers to bypass throttling and resource limits. This leads to excessive CPU and memory consumption, resulting in denial of service. The issue is referred to as the "MadeYouReset" attack. Red Hat has issued a security advisory and released a patch update for the Red Hat Offline Knowledge Portal container image that mitigates this vulnerability. However, no comprehensive mitigation is currently available for all affected products. The vulnerability is rated as important/high severity due to ease of exploitation and impact on service availability.
Potential Impact
Exploitation of this vulnerability can cause denial of service by exhausting server CPU and memory resources through repeated server-side stream resets triggered by malformed HTTP/2 requests. This can degrade or disrupt service availability for legitimate users. The vulnerability requires no authentication and can be exploited remotely over the network. No confidentiality or integrity impacts are reported. There are no known exploits in the wild at this time.
Mitigation Recommendations
Red Hat has released an updated container image for the Red Hat Offline Knowledge Portal that includes mitigations for CVE-2025-5115. Users should update to this version by pulling the updated container image from the Red Hat container registry using a valid subscription. Currently, no other mitigation meets Red Hat's standards for usability and stability. Users should monitor Red Hat advisories for future updates and consider applying the available update to affected products where applicable.
Red Hat Security Advisory: Red Hat Product OCP Tools 4.19 OpenShift Jenkins security update
Description
Jenkins is a continuous integration server that monitors executions of repeated jobs, such as building a software project or jobs run by cron. Security Fix(es): * jenkins: HTTP/2 (including DNS over HTTPS) contains a design flaw and is vulnerable to "MadeYouReset" DoS attack through HTTP/2 control frames (CVE-2025-5115) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page listed in the References section.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability identified as CVE-2025-5115 affects HTTP/2 implementations in Jetty components and Netty's HTTP/2 codec. It arises from an implementation weakness where malformed client requests cause server-side stream resets without triggering abuse counters, allowing attackers to bypass throttling and resource limits. This leads to excessive CPU and memory consumption, resulting in denial of service. The issue is referred to as the "MadeYouReset" attack. Red Hat has issued a security advisory and released a patch update for the Red Hat Offline Knowledge Portal container image that mitigates this vulnerability. However, no comprehensive mitigation is currently available for all affected products. The vulnerability is rated as important/high severity due to ease of exploitation and impact on service availability.
Potential Impact
Exploitation of this vulnerability can cause denial of service by exhausting server CPU and memory resources through repeated server-side stream resets triggered by malformed HTTP/2 requests. This can degrade or disrupt service availability for legitimate users. The vulnerability requires no authentication and can be exploited remotely over the network. No confidentiality or integrity impacts are reported. There are no known exploits in the wild at this time.
Mitigation Recommendations
Red Hat has released an updated container image for the Red Hat Offline Knowledge Portal that includes mitigations for CVE-2025-5115. Users should update to this version by pulling the updated container image from the Red Hat container registry using a valid subscription. Currently, no other mitigation meets Red Hat's standards for usability and stability. Users should monitor Red Hat advisories for future updates and consider applying the available update to affected products where applicable.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2025:14911
- Cve Count
- 2
- Additional Cves
- ["CVE-2025-55163"]
Threat ID: 6a294d7f8dd33fbd853ac8a4
Added to database: 06/10/2026, 11:41:51 UTC
Last enriched: 08/16/2026, 18:21:49 UTC
Last updated: 09/10/2026, 19:36:51 UTC
Views: 119
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.