Description
A flaw was found in the DERDecoder class within wildfly-elytron-asn1. A remote attacker can exploit this resource exhaustion vulnerability by sending a specially crafted DER (Distinguished Encoding Rules) payload. The decoder attempts to allocate excessive memory based on an inflated length value without proper validation, leading to Java Virtual Machine (JVM) memory exhaustion. This results in a remote Denial of Service (DoS) for services that process untrusted DER/ASN.1 input, including SASL (Simple Authentication and Security Layer) authentication mechanisms and X.500 certificate principal parsing paths.
Published: 2026-09-18
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via memory exhaustion
Action: Apply patch
AI Analysis

Impact

A flaw in the DERDecoder class of the wildfly-elytron-asn1 module allows a remote attacker to trigger unbounded memory allocation by sending a specially crafted DER payload. The decoder interprets an inflated length field and attempts to allocate excessively large buffers, exhausting JVM memory and causing the affected Java process to terminate or become unresponsive. The impact is a denial of service for any services that parse DER/ASN.1 data, such as SASL authentication mechanisms and X.500 certificate principal parsing paths, compromising availability but not confidentiality or integrity.

Affected Systems

Affected products include Red Hat Cryostat 4, Red Hat Red Hat Build of Keycloak, Red Hat Red Hat Data Grid 8, Red Hat Red Hat Fuse 7, Red Hat7 and 8, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat Lightspeed for Runtimes Operator, Red Hat Process Automation 7, Red Hat Red Hat Single Sign‑On 7, Red Hat build of Apache Camel HawtIO 4, Red Hat build of Apache Camel 4 for Quarkus 3, Red Hat build of Debezium 3, and Red Hat build of Quarkus. All labeled versions carry the vulnerability as deployed in the wildfly-elytron-asn1 component.

Risk and Exploitability

The CVSS score of 5.9 indicates medium severity. EPSS data is represented as < 1%, indicating a very low but nonzero exploitation probability, and the vulnerability is not listed in CISA KEV. The likely attack vector is remote network traffic that delivers a crafted DER payload. An attacker only needs to interact with a service that invokes the vulnerable decoder—common targets are SASL authentication endpoints or X.500 processing components—without authentication. Successful exploitation results in JVM memory exhaustion and service denial, with no known way to escape the isolated Java process or achieve code execution.

Generated by OpenCVE AI on September 19, 2026 at 18:38 UTC.

Remediation

Vendor Workaround

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.


OpenCVE Recommended Actions

  • Install any Red Hat security update that addresses the DERDecoder issue as soon as it is released.
  • Limit inbound traffic to services that parse DER/ASN.1 data (e.g., SASL endpoints) using firewalls or network policies to reduce the attack surface.
  • Monitor JVM memory utilization and restart affected services when memory usage spikes to prevent prolonged downtime.

Generated by OpenCVE AI on September 19, 2026 at 18:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:jboss_enterprise_application_platform:8 cpe:/a:redhat:jboss_enterprise_application_platform:8.1::el10
cpe:/a:redhat:jboss_enterprise_application_platform:8.1::el8
cpe:/a:redhat:jboss_enterprise_application_platform:8.1::el9
References

Mon, 21 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Redhat build Of Apache Camel - Hawtio
Redhat build Of Apache Camel For Quarkus
Redhat build Of Debezium 3
Redhat build Of Keycloak
Redhat build Of Quarkus
Redhat data Grid 8
Redhat jboss Enterprise Application Platform Expansion Pack
Redhat process Automation
Redhat quay 3
Redhat single Sign-on
Vendors & Products Redhat build Of Apache Camel - Hawtio
Redhat build Of Apache Camel For Quarkus
Redhat build Of Debezium 3
Redhat build Of Keycloak
Redhat build Of Quarkus
Redhat data Grid 8
Redhat jboss Enterprise Application Platform Expansion Pack
Redhat process Automation
Redhat quay 3
Redhat single Sign-on

Sat, 19 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Fri, 18 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Description A flaw was found in the DERDecoder class within wildfly-elytron-asn1. A remote attacker can exploit this resource exhaustion vulnerability by sending a specially crafted DER (Distinguished Encoding Rules) payload. The decoder attempts to allocate excessive memory based on an inflated length value without proper validation, leading to Java Virtual Machine (JVM) memory exhaustion. This results in a remote Denial of Service (DoS) for services that process untrusted DER/ASN.1 input, including SASL (Simple Authentication and Security Layer) authentication mechanisms and X.500 certificate principal parsing paths.
Title Org.wildfly.security/wildfly-elytron-asn1: unbounded memory allocation in wildfly elytron asn.1 derdecoder via crafted der payload
First Time appeared Redhat
Redhat apache Camel Hawtio
Redhat build Keycloak
Redhat camel Quarkus
Redhat cryostat
Redhat debezium
Redhat jboss Data Grid
Redhat jboss Enterprise Application Platform
Redhat jboss Enterprise Bpms Platform
Redhat jboss Fuse
Redhat jbosseapxp
Redhat lightspeed For Runtimes
Redhat quarkus
Redhat red Hat Single Sign On
Weaknesses CWE-770
CPEs cpe:/a:redhat:apache_camel_hawtio:4
cpe:/a:redhat:build_keycloak:
cpe:/a:redhat:camel_quarkus:3
cpe:/a:redhat:cryostat:4
cpe:/a:redhat:debezium:3
cpe:/a:redhat:jboss_data_grid:8
cpe:/a:redhat:jboss_enterprise_application_platform:7
cpe:/a:redhat:jboss_enterprise_application_platform:8
cpe:/a:redhat:jboss_enterprise_bpms_platform:7
cpe:/a:redhat:jboss_fuse:7
cpe:/a:redhat:jbosseapxp
cpe:/a:redhat:lightspeed_for_runtimes:1
cpe:/a:redhat:quarkus:3
cpe:/a:redhat:red_hat_single_sign_on:7
Vendors & Products Redhat
Redhat apache Camel Hawtio
Redhat build Keycloak
Redhat camel Quarkus
Redhat cryostat
Redhat debezium
Redhat jboss Data Grid
Redhat jboss Enterprise Application Platform
Redhat jboss Enterprise Bpms Platform
Redhat jboss Fuse
Redhat jbosseapxp
Redhat lightspeed For Runtimes
Redhat quarkus
Redhat red Hat Single Sign On
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Redhat Apache Camel Hawtio Build Keycloak Build Of Apache Camel - Hawtio Build Of Apache Camel For Quarkus Build Of Debezium 3 Build Of Keycloak Build Of Quarkus Camel Quarkus Cryostat Data Grid 8 Debezium Jboss Data Grid Jboss Enterprise Application Platform Jboss Enterprise Application Platform Expansion Pack Jboss Enterprise Bpms Platform Jboss Fuse Jbosseapxp Lightspeed For Runtimes Process Automation Quarkus Quay 3 Red Hat Single Sign On Single Sign-on
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-10-08T23:53:25.027Z

Reserved: 2026-06-04T10:22:47.465Z

Link: CVE-2026-10832

cve-icon Vulnrichment

Updated: 2026-09-18T15:34:02.514Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T15:17:04.710

Modified: 2026-10-09T00:17:07.573

Link: CVE-2026-10832

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-18T14:13:32Z

Links: CVE-2026-10832 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T19:25:28Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling