SB2026092928 - Multiple vulnerabilities in Wildfly Elytron
Published: September 29, 2026 Updated: September 30, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 vulnerabilities.
1) Authentication Bypass by Spoofing (CVE-ID: CVE-2026-85511)
CWE-ID: CWE-290 - Authentication Bypass by Spoofing
CVSSv4: 2.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to bypass authentication controls.
The vulnerability exists due to missing URL encoding in the Elytron token realm OAuth2 introspection handling when processing token authentication requests. A remote user can provide specially crafted token values to bypass authentication controls.
Only token realms configured both to handle authentication and to validate tokens through an introspection endpoint are affected.
2) Allocation of Resources Without Limits or Throttling (CVE-ID: CVE-2026-10832)
CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling
CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in the DERDecoder class when processing a crafted DER payload containing an inflated length value. A remote attacker can send a specially crafted DER payload to cause a denial of service.
This affects services that process untrusted DER/ASN.1 input, including SASL authentication mechanisms and X.500 certificate principal parsing paths.
Remediation
Install update from vendor's website.