Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-19611

Опубликовано: 24 июл. 2026
Источник: redhat
CVSS3: 7.4
EPSS Низкий

Описание

A flaw was found in WildFly Elytron. Password hashing and verification normalize input with Unicode NFKC, which can collapse fullwidth characters to ASCII equivalents. A remote attacker can more easily guess affected passwords by using an ASCII-only dictionary against accounts whose passwords were intended to include those non-ASCII characters, leading to unauthorized access.

Отчет

This issue has Moderate impact. Successful exploitation depends on accounts using fullwidth or other NFKC-compatibility characters in passwords and on the feasibility of password guessing against the deployed hash algorithm. Red Hat products that ship org.wildfly.security:wildfly-elytron-password-impl may be affected.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat build of Apache Camel 4 for Quarkus 3wildfly-elytron-password-implAffected
Red Hat build of Debezium 3wildfly-elytron-password-implAffected
Red Hat Build of Keycloakkeycloak/rhbk-openshift-rhel9Affected
Red Hat Build of Keycloakwildfly-elytron-password-implAffected
Red Hat build of Quarkuswildfly-elytron-password-implAffected
Red Hat Data Grid 8wildfly-elytron-password-implAffected
Red Hat JBoss Enterprise Application Platform 7jboss-eap-7/eap74-els-openjdk17-openshift-rhel8Will not fix
Red Hat JBoss Enterprise Application Platform 7jboss-eap-7/eap74-els-openjdk8-openshift-rhel8Will not fix
Red Hat JBoss Enterprise Application Platform 7wildfly-elytron-password-implWill not fix
Red Hat JBoss Enterprise Application Platform 8wildfly-elytron-password-implAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-173
https://bugzilla.redhat.com/show_bug.cgi?id=2514568wildfly-elytron: org.wildfly.security/wildfly-elytron-password-impl: wildfly-elytron: Password keyspace reduction via NFKC fullwidth folding

EPSS

Процентиль: 28%
0.00345
Низкий

7.4 High

CVSS3

Связанные уязвимости

CVSS3: 7.4
nvd
около 1 месяца назад

A flaw was found in WildFly Elytron. Password hashing and verification normalize input with Unicode NFKC, which can collapse fullwidth characters to ASCII equivalents. A remote attacker can more easily guess affected passwords by using an ASCII-only dictionary against accounts whose passwords were intended to include those non-ASCII characters, leading to unauthorized access.

CVSS3: 7.4
github
около 1 месяца назад

A flaw was found in WildFly Elytron. Password hashing and verification normalize input with Unicode NFKC, which can collapse fullwidth characters to ASCII equivalents. A remote attacker can more easily guess affected passwords by using an ASCII-only dictionary against accounts whose passwords were intended to include those non-ASCII characters, leading to unauthorized access.

EPSS

Процентиль: 28%
0.00345
Низкий

7.4 High

CVSS3

Уязвимость CVE-2026-19611