CVE-2024-1635 | Undertow: out-of-memory error after several closed connections with wildfly-http-client protocol

A vulnerability was found in Undertow. This vulnerability impacts a server that supports the wildfly-http-client protocol. Whenever a malicious user opens and closes a connection with the HTTP port of the server and then closes the connection immediately, the server will end with both memory and open file limits exhausted at some point, depending on the amount of memory available. At HTTP upgrade to remoting, the WriteTimeoutStreamSinkConduit leaks connections if RemotingConnection is closed by Remoting ServerConnectionOpenListener. Because the remoting connection originates in Undertow as part of the HTTP upgrade, there is an external layer to the remoting connection. This connection is unaware of the outermost layer when closing the connection during the connection opening procedure. Hence, the Undertow WriteTimeoutStreamSinkConduit is not notified of the closed connection in this scenario. Because WriteTimeoutStreamSinkConduit creates a timeout task, the whole dependency tree leaks via that task, which is added to XNIO WorkerThread. So, the workerThread points to the Undertow conduit, which contains the connections and causes the leak.

Published: 2024-02-19 Last update: 2025-06-25 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2024-1635 is rated Moderate Risk (63.1/100): CVSS High severity, with high exploitation likelihood (EPSS 22.69%, 96th percentile). Core evidence: EPSS ranks this CVE among the most likely to be exploited in the near term. Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2024-1635

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-05-07 23.14% 22.69% -0.46%
2 2026-04-24 22.69% 23.14% +0.46%
3 2026-04-07 22.69%

Full EPSS history (52 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2024-1635

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
7.5 3.1 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Click to expand
Attack vector (AV:N)
Could be attacked over the internet or any normal routed network—not just someone sitting at the machine.
Attack complexity (AC:L)
Once they can reach the bug, pulling it off is straightforward—no weird race conditions or rare setup.
Privileges required (PR:N)
No account or special rights needed—anonymous or random user is enough.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:U)
Damage stays in the same “trust bubble” as the broken component—no big spill into unrelated systems.
Confidentiality (C:N)
Doesn’t really leak secrets in a meaningful way.
Integrity (I:N)
Data isn’t meaningfully altered or forged.
Availability (A:H)
Could take the service down hard or make it unusable for people who depend on it.
3.9 3.6 [email protected]

Weakness enumeration for CVE-2024-1635

GitHub Security Advisory for CVE-2024-1635

GHSA-w6qf-42m7-vh68 · Severity: high · Ecosystem: maven — Undertow Uncontrolled Resource Consumption Vulnerability

OS Trackers for CVE-2024-1635

vendor priority summary link
debian not yet assigned CVE-2024-1635 not yet assigned priority: Debian including 1 source packages (undertow), 2 status rows across 2 suites (forky, sid): resolved 2. https://security-tracker.debian.org/tracker/CVE-2024-1635
redhat high https://access.redhat.com/security/cve/CVE-2024-1635
ubuntu medium CVE-2024-1635 medium priority: Ubuntu including 1 source packages (undertow), 11 status rows across 11 suites (bionic, focal, jammy, mantic, noble, oracular, plucky, questing, trusty, upstream, xenial): needs-triage 7, DNE 2, ignored 2. https://ubuntu.com/security/CVE-2024-1635

Affected software / configurations for CVE-2024-1635

Vendor Product Version Raw CPE
netapp active_iq_unified_manager cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:linux:*:*
netapp active_iq_unified_manager cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*
netapp active_iq_unified_manager cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:*
netapp oncommand_workflow_automation cpe:2.3:a:netapp:oncommand_workflow_automation:-:*:*:*:*:*:*:*
redhat fuse 1.0 cpe:2.3:a:redhat:fuse:1.0:*:*:*:*:*:*:*
redhat integration_camel_for_spring_boot cpe:2.3:a:redhat:integration_camel_for_spring_boot:-:*:*:*:*:*:*:*
redhat jboss_enterprise_application_platform 7.4 cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.4:*:*:*:*:*:*:*
redhat openshift_container_platform 4.11 cpe:2.3:a:redhat:openshift_container_platform:4.11:*:*:*:*:*:*:*
redhat openshift_container_platform 4.12 cpe:2.3:a:redhat:openshift_container_platform:4.12:*:*:*:*:*:*:*
redhat openshift_container_platform_for_linuxone 4.9 cpe:2.3:a:redhat:openshift_container_platform_for_linuxone:4.9:*:*:*:*:*:*:*
redhat openshift_container_platform_for_linuxone 4.10 cpe:2.3:a:redhat:openshift_container_platform_for_linuxone:4.10:*:*:*:*:*:*:*
redhat openshift_container_platform_for_power 4.9 cpe:2.3:a:redhat:openshift_container_platform_for_power:4.9:*:*:*:*:*:*:*
redhat openshift_container_platform_for_power 4.10 cpe:2.3:a:redhat:openshift_container_platform_for_power:4.10:*:*:*:*:*:*:*
redhat single_sign-on cpe:2.3:a:redhat:single_sign-on:-:*:*:*:text-only:*:*:*
redhat single_sign-on 7.6 cpe:2.3:a:redhat:single_sign-on:7.6:*:*:*:*:*:*:*

References for CVE-2024-1635

URL Tags
https://access.redhat.com/errata/RHSA-2024:1674 Third Party Advisory
https://access.redhat.com/errata/RHSA-2024:1675 Third Party Advisory
https://access.redhat.com/errata/RHSA-2024:1676 Third Party Advisory
https://access.redhat.com/errata/RHSA-2024:1677 Third Party Advisory
https://access.redhat.com/errata/RHSA-2024:1860 Third Party Advisory
https://access.redhat.com/errata/RHSA-2024:1861 Third Party Advisory
https://access.redhat.com/errata/RHSA-2024:1862 Third Party Advisory
https://access.redhat.com/errata/RHSA-2024:1864 Third Party Advisory
https://access.redhat.com/errata/RHSA-2024:1866 Third Party Advisory
https://access.redhat.com/errata/RHSA-2024:3354 Third Party Advisory
https://access.redhat.com/errata/RHSA-2024:4884 Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:4226 Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:9583
https://access.redhat.com/security/cve/CVE-2024-1635 Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2264928 Third Party Advisory
https://security.netapp.com/advisory/ntap-20240322-0007/ Vendor Advisory
cvelogic Threat Intelligence