Impact
A flaw in the DERDecoder class of the wildfly-elytron-asn1 module allows a remote attacker to trigger unbounded memory allocation by sending a specially crafted DER payload. The decoder interprets an inflated length field and attempts to allocate excessively large buffers, exhausting JVM memory and causing the affected Java process to terminate or become unresponsive. The impact is a denial of service for any services that parse DER/ASN.1 data, such as SASL authentication mechanisms and X.500 certificate principal parsing paths, compromising availability but not confidentiality or integrity.
Affected Systems
Affected products include Red Hat Cryostat 4, Red Hat Red Hat Build of Keycloak, Red Hat Red Hat Data Grid 8, Red Hat Red Hat Fuse 7, Red Hat7 and 8, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat Lightspeed for Runtimes Operator, Red Hat Process Automation 7, Red Hat Red Hat Single Sign‑On 7, Red Hat build of Apache Camel HawtIO 4, Red Hat build of Apache Camel 4 for Quarkus 3, Red Hat build of Debezium 3, and Red Hat build of Quarkus. All labeled versions carry the vulnerability as deployed in the wildfly-elytron-asn1 component.
Risk and Exploitability
The CVSS score of 5.9 indicates medium severity. EPSS data is represented as < 1%, indicating a very low but nonzero exploitation probability, and the vulnerability is not listed in CISA KEV. The likely attack vector is remote network traffic that delivers a crafted DER payload. An attacker only needs to interact with a service that invokes the vulnerable decoder—common targets are SASL authentication endpoints or X.500 processing components—without authentication. Successful exploitation results in JVM memory exhaustion and service denial, with no known way to escape the isolated Java process or achieve code execution.
OpenCVE Enrichment