Resource Exhaustion Vulnerability in Wildfly-Elytron-ASN1 by Red Hat
CVE-2026-10832

5.9MEDIUM

What is CVE-2026-10832?

A flaw exists in the DERDecoder class of Wildfly-Elytron-ASN1, which can be exploited through sending a specially crafted DER payload. This vulnerability allows remote attackers to cause Java Virtual Machine memory exhaustion by manipulating the memory allocation process using an inflated length value. If services that process untrusted DER/ASN.1 input, such as SASL authentication mechanisms and X.500 certificate parsing, are targeted, they may be rendered unavailable, leading to a Denial of Service condition.

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.