CVE-2024-1635

HIGH
Published Feb 19, 2024 Modified Jun 25, 2025 CWE-400

Description

A vulnerability was found in Undertow. This vulnerability impacts a server that supports the wildfly-http-client protocol. Whenever a malicious user opens and closes a connection with the HTTP port of the server and then closes the connection immediately, the server will end with both memory and open file limits exhausted at some point, depending on the amount of memory available. At HTTP upgrade to remoting, the WriteTimeoutStreamSinkConduit leaks connections if RemotingConnection is closed by Remoting ServerConnectionOpenListener. Because the remoting connection originates in Undertow as part of the HTTP upgrade, there is an external layer to the remoting connection. This connection is unaware of the outermost layer when closing the connection during the connection opening procedure. Hence, the Undertow WriteTimeoutStreamSinkConduit is not notified of the closed connection in this scenario. Because WriteTimeoutStreamSinkConduit creates a timeout task, the whole dependency tree leaks via that task, which is added to XNIO WorkerThread. So, the workerThread points to the Undertow conduit, which contains the connections and causes the leak.

Is your site exposed to CVE-2024-1635?

Run a free security scan — no signup, results in seconds.

CVSS v3.1 Score

7.5
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Weakness Type (CWE)

CWE-400 Uncontrolled Resource Consumption

Affected Products

Vendor Product
netapp active_iq_unified_manager
netapp active_iq_unified_manager
netapp active_iq_unified_manager
netapp oncommand_workflow_automation
redhat fuse
redhat integration_camel_for_spring_boot
redhat jboss_enterprise_application_platform
redhat openshift_container_platform
redhat openshift_container_platform
redhat openshift_container_platform_for_linuxone
redhat openshift_container_platform_for_linuxone
redhat openshift_container_platform_for_power
redhat openshift_container_platform_for_power
redhat single_sign-on
redhat single_sign-on

References

Frequently Asked Questions

What is CVE-2024-1635? +
A vulnerability was found in Undertow. This vulnerability impacts a server that supports the wildfly-http-client protocol. Whenever a malicious user opens and closes a connection with the HTTP port of the server and then closes the connection immediately, the server will end with both memory and open file limits exhausted at some point, depending on the amount of memory available. At HTTP upgrade to remoting, the WriteTimeoutStreamSinkConduit leaks connections if RemotingConnection is closed by Remoting ServerConnectionOpenListener. Because the remoting connection originates in Undertow as part of the HTTP upgrade, there is an external layer to the remoting connection. This connection is unaware of the outermost layer when closing the connection during the connection opening procedure. Hence, the Undertow WriteTimeoutStreamSinkConduit is not notified of the closed connection in this scenario. Because WriteTimeoutStreamSinkConduit creates a timeout task, the whole dependency tree leaks via that task, which is added to XNIO WorkerThread. So, the workerThread points to the Undertow conduit, which contains the connections and causes the leak. It has a CVSS v3.1 base score of 7.5 (HIGH).
How severe is CVE-2024-1635? +
CVE-2024-1635 has a CVSS v3.1 score of 7.5 out of 10, rated HIGH. This is a high-severity vulnerability that should be prioritized for patching.
What products are affected by CVE-2024-1635? +
CVE-2024-1635 affects products from netapp, redhat, specifically: active_iq_unified_manager, fuse, integration_camel_for_spring_boot, jboss_enterprise_application_platform, oncommand_workflow_automation, openshift_container_platform, openshift_container_platform_for_linuxone, openshift_container_platform_for_power, single_sign-on. Check the affected products table above for specific version ranges.
How do I check if I'm vulnerable to CVE-2024-1635? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.

Related Vulnerabilities

Don't wait for an exploit

Scan your website for vulnerabilities like CVE-2024-1635 — free, no signup required.