Allocation of Resources Without Limits or Throttling in Wildfly Elytron - CVE-2026-10832
Published: September 29, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in the DERDecoder class when processing a crafted DER payload containing an inflated length value. A remote attacker can send a specially crafted DER payload to cause a denial of service.
This affects services that process untrusted DER/ASN.1 input, including SASL authentication mechanisms and X.500 certificate principal parsing paths.