Junglewise Threat Intelligence

CVE-2026-10832: WildFly Elytron ASN.1 resource exhaustion in DER decoder

CVE-2026-10832 · Severity: medium · CVSS 5.9 · Published 2026-09-18

Vendors: Red Hat.

Executive brief

WildFly Elytron is a Java security library used in enterprise application servers for authentication and authorization. A flaw in its DER decoder allows remote attackers to send specially crafted data that causes excessive memory allocation, exhausting server resources and causing a denial of service. This affects services using SASL authentication or certificate processing.

Technical details

The vulnerability exists in the DERDecoder class of wildfly-elytron-asn1, where ASN.1 Distinguished Encoding Rules (DER) payloads are parsed. The decoder fails to validate length fields before allocating memory, allowing an attacker to specify an inflated length value that causes the JVM to attempt excessive memory allocation. This is a remote denial-of-service vector requiring only network reachability to a service processing untrusted DER/ASN.1 input, such as SASL authentication handlers or X.500 certificate principal parsers. No authentication is required. A patch should be available from Red Hat/WildFly.

Affected products

  • Red Hat WildFly Elytron <UNKNOWN>

Timeline

  • 2026-09-18: disclosed

References

Related threats