---
id: CVE-2024-3653
title: A vulnerability was found in Undertow
summary: >-
  A vulnerability was found in Undertow. This issue requires enabling the
  learning-push handler in the server's config, which is disabled by default,
  leaving the maxAge config in the handler unconfigured. The default is -1,
  which makes the…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'
cwe:
  - CWE-401
vendor: Red Hat
product: undertow
affected:
  - undertow <= 2.3.14.Final
  - io.quarkus.http/quarkus-http-core (all versions)
  - io.undertow/undertow-core (all versions)
  - eap7-undertow (all versions)
  - eap7-undertow (all versions)
  - eap7-undertow (all versions)
  - undertow
  - undertow (all versions)
  - undertow (all versions)
  - undertow (all versions)
  - undertow
  - undertow
  - undertow
  - undertow (all versions)
  - quarkus-undertow
  - undertow (all versions)
  - undertow
  - undertow (all versions)
  - undertow (all versions)
  - undertow
  - undertow
  - undertow
  - undertow
  - undertow (all versions)
  - undertow (all versions)
published: '2024-07-08'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T23:17:20.767'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-3653'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2024:4392'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:5143'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:5144'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:5145'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:5147'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:6437'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2024-3653'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2274437'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:4392'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/security/cve/CVE-2024-3653'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2274437'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20240828-0002/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-3653.json
  - url: 'https://www.cve.org/CVERecord?id=CVE-2024-3653'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2024-3653'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2025-01-09T21:35:33.839379Z'
epss: 0.01866
epssPercentile: 0.78399
ingestedAt: '2026-08-05T11:47:23.359Z'
patched:
  - jboss_eap_7_4_for_rhel_7_server
  - jboss_eap_7_4_for_rhel 8
  - jboss_eap_7_4_for_rhel 9
  - jboss_enterprise_application_platform 8
  - jboss_enterprise_application_platform
  - build_of_quarkus 3.8.6.redhat
---

## Overview

A vulnerability was found in Undertow. This issue requires enabling the learning-push handler in the server's config, which is disabled by default, leaving the maxAge config in the handler unconfigured. The default is -1, which makes the handler vulnerable. If someone overwrites that config, the server is not subject to the attack. The attacker needs to be able to reach the server with a normal HTTP request.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **RHSA-2024:5143** · Red Hat · fixed in: Red Hat JBoss EAP 7.4 for RHEL 7 Server · released 2024-08-08 · [advisory](https://access.redhat.com/errata/RHSA-2024:5143)
- **RHSA-2024:5144** · Red Hat · fixed in: Red Hat JBoss EAP 7.4 for RHEL 8 · released 2024-08-08 · [advisory](https://access.redhat.com/errata/RHSA-2024:5144)
- **RHSA-2024:5145** · Red Hat · fixed in: Red Hat JBoss EAP 7.4 for RHEL 9 · released 2024-08-08 · [advisory](https://access.redhat.com/errata/RHSA-2024:5145)
- **RHSA-2024:4392** · Red Hat · fixed in: Red Hat JBoss Enterprise Application Platform 8 · released 2024-07-08 · [advisory](https://access.redhat.com/errata/RHSA-2024:4392)
- **RHSA-2024:5147** · Red Hat · fixed in: Red Hat JBoss Enterprise Application Platform · released 2024-08-08 · [advisory](https://access.redhat.com/errata/RHSA-2024:5147)
- **RHSA-2024:6437** · Red Hat · fixed in: Red Hat build of Quarkus 3.8.6.redhat · released 2024-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2024:6437)
- **Red Hat VEX** · Low · affected: OpenShift Serverless, Red Hat build of Apache Camel 4 for Quarkus 3, Red Hat build of Apache Camel for Spring Boot 4, Red Hat build of OptaPlanner 8, Red Hat Data Grid 8, Red Hat Fuse 7, … · no fix planned: Red Hat Fuse 7, Red Hat JBoss Data Grid 7, Red Hat JBoss Fuse Service Works 6, Red Hat Process Automation 7, … · updated 2026-09-08 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-3653.json)
