A flaw was found in WildFly Elytron. Password hashing and verification normalize input with Unicode NFKC, which can collapse fullwidth characters to ASCII equivalents. A remote attacker can more easily guess affected passwords by using an ASCII-only dictionary against accounts whose passwords were intended to include those non-ASCII characters, leading to unauthorized access.
Metrics
Affected Vendors & Products
References
History
Thu, 20 Aug 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in WildFly Elytron. Password hashing and verification normalize input with Unicode NFKC, which can collapse fullwidth characters to ASCII equivalents. A remote attacker can more easily guess affected passwords by using an ASCII-only dictionary against accounts whose passwords were intended to include those non-ASCII characters, leading to unauthorized access. | |
| Title | Wildfly-elytron: org.wildfly.security/wildfly-elytron-password-impl: wildfly-elytron: password keyspace reduction via nfkc fullwidth folding | |
| First Time appeared |
Redhat
Redhat build Keycloak Redhat camel Quarkus Redhat debezium Redhat jboss Data Grid Redhat jboss Enterprise Application Platform Redhat jbosseapxp Redhat quarkus Redhat red Hat Single Sign On |
|
| Weaknesses | CWE-173 | |
| CPEs | cpe:/a:redhat:build_keycloak: cpe:/a:redhat:camel_quarkus:3 cpe:/a:redhat:debezium:3 cpe:/a:redhat:jboss_data_grid:8 cpe:/a:redhat:jboss_enterprise_application_platform:7 cpe:/a:redhat:jboss_enterprise_application_platform:8 cpe:/a:redhat:jbosseapxp cpe:/a:redhat:quarkus:3 cpe:/a:redhat:red_hat_single_sign_on:7 |
|
| Vendors & Products |
Redhat
Redhat build Keycloak Redhat camel Quarkus Redhat debezium Redhat jboss Data Grid Redhat jboss Enterprise Application Platform Redhat jbosseapxp Redhat quarkus Redhat red Hat Single Sign On |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-08-20T15:58:24.190Z
Reserved: 2026-08-12T11:04:06.893Z
Link: CVE-2026-19611
No data.
Status : Received
Published: 2026-08-20T16:17:18.293
Modified: 2026-08-20T16:17:18.293
Link: CVE-2026-19611
No data.
OpenCVE Enrichment
Updated: 2026-08-20T21:15:05Z