# Security Brief: CVE-2024-5971 Undertow TLS 1.3 Chunked Response Flaw Can Cause DoS

Canonical: https://vulnify.app/blog/security-brief-cve-2024-5971-undertow-tls13-chunked-response-dos

CVE-2024-5971 is an Undertow denial-of-service flaw affecting a specific Java 17 and TLS 1.3 response-handling scenario. Teams should verify package versions, runtime conditions, and patch status.

What happened CVE-2024-5971 is a denial-of-service vulnerability in Undertow, the Java web server and servlet-container technology used in several Java application stacks. The flaw occurs when a chunked response is flushed but Undertow fails to send the expected terminating 0 chunk. The response headers and body may already have been sent, yet the client continues waiting while server-side resources remain tied up. Red Hat states that the condition occurs specifically in Java 17 with TLS 1.3. The CNA vector is network-accessible with low attack complexity, no privileges, and no user interaction, with availability as the affected security property. GitHub's reviewed advisory lists patched Undertow Core versions 2.3.15.Final and 2.2.34.Final. This CVE was originally published in July 2024. It can still matter in 2026 where older Undertow packages remain deployed, but it should not be presented as a newly disclosed 2026 vulnerability. Why it matters for website owners The issue is narrowly conditional, but availability bugs can become operationally serious when the affected configuration sits behind a public Java application. Repeated requests that leave responses hanging can consume server resources and degrade service for legitimate users. A public TLS scan cannot confirm this CVE because the root cause is inside Undertow's response handling. Website owners need package and runtime inventory to determine whether Java 17, TLS 1.3, and an affected Undertow version intersect on the same service. What to check on your site Identify internet-facing applications using Undertow or application platforms that embed it. Check the deployed Undertow Core version. GitHub lists 2.3.15.Final and 2.2.34.Final as patched releases for the affected branches. Confirm whether the service runs on Java 17 with TLS 1.3, the scenario described by Red Hat and NVD. Apply vendor-supported updates rather than changing TLS settings as a substitute for patching. Monitor connection counts, worker saturation, response completion, memory, and request latency for signs of resource exhaustion. Use Vulnify's TLS Deep Analysis to review the public protocol, cipher, certificate lifecycle, and chain configuration. The SSL Checker can provide a faster public certificate and TLS baseline. Neither tool identifies the installed Undertow package version. Related reading For transport-layer context, see SSL/TLS Security Explained: Risks, Attacks and Best Practice . If Undertow is deployed behind a load balancer, ingress controller, or CDN, also review Reverse Proxy Security for TLS termination and upstream trust-boundary considerations. Sources NIST NVD GitHub Advisory Database
