Executive brief
WildFly Elytron is a security framework used in enterprise Java application servers to manage authentication and password verification. A flaw in its password normalization process allows attackers to bypass password security by using basic ASCII dictionary attacks against accounts with non-ASCII characters, potentially leading to unauthorized access and account compromise.
Technical details
The vulnerability stems from WildFly Elytron's use of Unicode NFKC normalization during password hashing and verification. NFKC normalization collapses fullwidth characters (such as full-width Latin or CJK variants) to their ASCII equivalents, reducing password entropy. An attacker with network access can perform offline dictionary attacks using ASCII-only passwords against accounts that were intended to have fullwidth or other non-ASCII characters, effectively lowering the security of such passwords. The flaw affects the password validation component during authentication. Patches are available from Red Hat.
Affected products
- Red Hat WildFly Elytron
Timeline
- 2026-08-20: disclosed