CVE-2026-19611
Wildfly-elytron: org.wildfly.security/wildfly-elytron-password-impl: wildfly-elytron: password keyspace reduction via nfkc fullwidth folding
CVSS Score
7.4
EPSS Score
0.0%
EPSS Percentile
0th
A flaw was found in WildFly Elytron. Password hashing and verification normalize input with Unicode NFKC, which can collapse fullwidth characters to ASCII equivalents. A remote attacker can more easily guess affected passwords by using an ASCII-only dictionary against accounts whose passwords were intended to include those non-ASCII characters, leading to unauthorized access.
| CWE | CWE-173 |
| Vendor | red hat |
| Product | red hat build of apache camel 4 for quarkus 3 |
| Published | Aug 20, 2026 |
Stay Ahead of the Next One
Get instant alerts for red hat red hat build of apache camel 4 for quarkus 3
Be the first to know when new high vulnerabilities affecting red hat red hat build of apache camel 4 for quarkus 3 are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
Affected Versions
Red Hat / Red Hat build of Apache Camel 4 for Quarkus 3
All versions affected Red Hat / Red Hat build of Debezium 3
All versions affected Red Hat / Red Hat Build of Keycloak
All versions affected Red Hat / Red Hat Build of Keycloak
All versions affected Red Hat / Red Hat build of Quarkus
All versions affected Red Hat / Red Hat Data Grid 8
All versions affected Red Hat / Red Hat JBoss Enterprise Application Platform 7
All versions affected Red Hat / Red Hat JBoss Enterprise Application Platform 7
All versions affected Red Hat / Red Hat JBoss Enterprise Application Platform 7
All versions affected Red Hat / Red Hat JBoss Enterprise Application Platform 8
All versions affected Red Hat / Red Hat JBoss Enterprise Application Platform Expansion Pack
All versions affected Red Hat / Red Hat Single Sign-On 7
All versions affected References
Credits
Upstream acknowledges LiuBo-keep (aidan) as the original reporter.