๐Ÿ” CVE Alert

CVE-2026-19611

HIGH 7.4

Wildfly-elytron: org.wildfly.security/wildfly-elytron-password-impl: wildfly-elytron: password keyspace reduction via nfkc fullwidth folding

CVSS Score
7.4
EPSS Score
0.0%
EPSS Percentile
0th

A flaw was found in WildFly Elytron. Password hashing and verification normalize input with Unicode NFKC, which can collapse fullwidth characters to ASCII equivalents. A remote attacker can more easily guess affected passwords by using an ASCII-only dictionary against accounts whose passwords were intended to include those non-ASCII characters, leading to unauthorized access.

CWE CWE-173
Vendor red hat
Product red hat build of apache camel 4 for quarkus 3
Published Aug 20, 2026
Stay Ahead of the Next One

Get instant alerts for red hat red hat build of apache camel 4 for quarkus 3

Be the first to know when new high vulnerabilities affecting red hat red hat build of apache camel 4 for quarkus 3 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None

Affected Versions

Red Hat / Red Hat build of Apache Camel 4 for Quarkus 3
All versions affected
Red Hat / Red Hat build of Debezium 3
All versions affected
Red Hat / Red Hat Build of Keycloak
All versions affected
Red Hat / Red Hat Build of Keycloak
All versions affected
Red Hat / Red Hat build of Quarkus
All versions affected
Red Hat / Red Hat Data Grid 8
All versions affected
Red Hat / Red Hat JBoss Enterprise Application Platform 7
All versions affected
Red Hat / Red Hat JBoss Enterprise Application Platform 7
All versions affected
Red Hat / Red Hat JBoss Enterprise Application Platform 7
All versions affected
Red Hat / Red Hat JBoss Enterprise Application Platform 8
All versions affected
Red Hat / Red Hat JBoss Enterprise Application Platform Expansion Pack
All versions affected
Red Hat / Red Hat Single Sign-On 7
All versions affected

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
access.redhat.com: https://access.redhat.com/security/cve/CVE-2026-19611 bugzilla.redhat.com: https://bugzilla.redhat.com/show_bug.cgi?id=2514568

Credits

Upstream acknowledges LiuBo-keep (aidan) as the original reporter.