CVE-2024-5971: Uncontrolled Recursion in Red Hat Red Hat build of Apache Camel 3.20.7 for Spring Boot
A vulnerability was found in Undertow, where the chunked response hangs after the body was flushed. The response headers and body were sent but the client would continue waiting as Undertow does not send the expected 0\r\n termination of the chunked response. This results in uncontrolled resource consumption, leaving the server side to a denial of service attack. This happens only with Java 17 TLSv1.3 scenarios.
AI Analysis
Technical Summary
The vulnerability CVE-2024-5971 in Undertow causes the chunked HTTP response to hang after the response body is flushed because the expected 0\r\n termination of the chunked response is not sent. This results in the client waiting indefinitely, leading to uncontrolled resource consumption on the server side and a denial of service condition. The issue specifically occurs in Java 17 TLSv1.3 NewSessionTicket scenarios. Red Hat advisories confirm the vulnerability affects Red Hat JBoss Enterprise Application Platform 8.0 and related Undertow components. Security updates have been issued to fix this problem.
Potential Impact
The vulnerability leads to denial of service by causing the server to consume resources uncontrollably when handling chunked HTTP responses under Java 17 TLSv1.3. There is no impact on confidentiality or integrity, but availability is severely affected. No known exploits in the wild have been reported at this time.
Mitigation Recommendations
Red Hat has released security updates addressing CVE-2024-5971 in Red Hat JBoss Enterprise Application Platform 8.0 and related Undertow components. Users should apply these official patches as per Red Hat's advisories (e.g., RHSA-2024:4392 and RHSA-2024:4884). Before applying updates, ensure all previous errata are applied. Patch status is confirmed as fixed in these advisories. No additional mitigation steps are indicated beyond applying the vendor-provided updates.
CVE-2024-5971: Uncontrolled Recursion in Red Hat Red Hat build of Apache Camel 3.20.7 for Spring Boot
Description
A vulnerability was found in Undertow, where the chunked response hangs after the body was flushed. The response headers and body were sent but the client would continue waiting as Undertow does not send the expected 0\r\n termination of the chunked response. This results in uncontrolled resource consumption, leaving the server side to a denial of service attack. This happens only with Java 17 TLSv1.3 scenarios.
CVSS v3.1
Score 7.5high
Affected software
Red Hat
Red Hat build of Apache Camel 3.20.7 for Spring Boot
Red Hat
Red Hat build of Apache Camel 4.4.1 for Spring Boot 3.2
Red Hat
Red Hat build of Apache Camel 4.4.2 for Spring Boot
Red Hat
Red Hat JBoss Enterprise Application Platform
Red Hat
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8
Red Hat
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9
Red Hat
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7
Red Hat
Red Hat JBoss Enterprise Application Platform 8
Red Hat
Red Hat build of Apache Camel for Spring Boot 3
Red Hat
Red Hat build of Apache Camel - HawtIO 4
Red Hat
Red Hat Build of Keycloak
Red Hat
Red Hat build of Quarkus
Red Hat
Red Hat Data Grid 8
Red Hat
Red Hat Fuse 7
Red Hat
Red Hat Integration Camel K 1
Red Hat
Red Hat JBoss Data Grid 7
Red Hat
Red Hat JBoss Enterprise Application Platform 7
Red Hat
Red Hat JBoss Enterprise Application Platform Expansion Pack
Red Hat
Red Hat Process Automation 7
Red Hat
Red Hat Single Sign-On 7
pkg:github/undertowRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability CVE-2024-5971 in Undertow causes the chunked HTTP response to hang after the response body is flushed because the expected 0\r\n termination of the chunked response is not sent. This results in the client waiting indefinitely, leading to uncontrolled resource consumption on the server side and a denial of service condition. The issue specifically occurs in Java 17 TLSv1.3 NewSessionTicket scenarios. Red Hat advisories confirm the vulnerability affects Red Hat JBoss Enterprise Application Platform 8.0 and related Undertow components. Security updates have been issued to fix this problem.
Potential Impact
The vulnerability leads to denial of service by causing the server to consume resources uncontrollably when handling chunked HTTP responses under Java 17 TLSv1.3. There is no impact on confidentiality or integrity, but availability is severely affected. No known exploits in the wild have been reported at this time.
Mitigation Recommendations
Red Hat has released security updates addressing CVE-2024-5971 in Red Hat JBoss Enterprise Application Platform 8.0 and related Undertow components. Users should apply these official patches as per Red Hat's advisories (e.g., RHSA-2024:4392 and RHSA-2024:4884). Before applying updates, ensure all previous errata are applied. Patch status is confirmed as fixed in these advisories. No additional mitigation steps are indicated beyond applying the vendor-provided updates.
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- redhat
- Date Reserved
- 2024-06-13T13:50:13.855Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/errata/RHSA-2024:4392","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2024:4884","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2024:5143","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2024:5144","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2024:5145","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2024:5147","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2024:6508","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2024:6883","vendor":"Red Hat"},{"url":"https://access.redhat.com/security/cve/CVE-2024-5971","vendor":"Red Hat"}]
Threat ID: 68faafd950358b89bd7bfd50
Added to database: 10/23/2025, 22:44:41 UTC
Last enriched: 08/09/2026, 12:57:04 UTC
Last updated: 09/10/2026, 19:46:23 UTC
Views: 497
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.