Bug 2484703 (CVE-2026-10832) - CVE-2026-10832 org.wildfly.security/wildfly-elytron-asn1: Unbounded Memory Allocation in WildFly Elytron ASN.1 DERDecoder via Crafted DER Payload
Summary: CVE-2026-10832 org.wildfly.security/wildfly-elytron-asn1: Unbounded Memory Al...
Keywords:
Status: NEW
Alias: CVE-2026-10832
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-06-04 10:25 UTC by OSIDB Bzimport
Modified: 2026-09-22 15:36 UTC (History)
76 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2026:70228 0 None None None 2026-09-22 12:56:35 UTC
Red Hat Product Errata RHSA-2026:70229 0 None None None 2026-09-22 13:01:09 UTC
Red Hat Product Errata RHSA-2026:70230 0 None None None 2026-09-22 12:59:03 UTC
Red Hat Product Errata RHSA-2026:70277 0 None None None 2026-09-22 15:36:09 UTC

Description OSIDB Bzimport 2026-06-04 10:25:32 UTC
A resource exhaustion vulnerability exists in the DERDecoder class within org.wildfly.security:wildfly-elytron-asn1, where primitive type decoders (decodeOctetString(), decodeBitString(), decodeInteger(), etc.) allocate a byte[] array based on the declared length field of a DER-encoded input without validating it against the actual remaining bytes in the buffer.
An attacker can craft a minimal 7-byte DER payload with an inflated length value, causing the decoder to attempt a multi-gigabyte heap allocation that exhausts JVM memory and triggers an OutOfMemoryError.
This results in a remote denial-of-service condition against any service endpoint that processes untrusted DER/ASN.1 input through the affected decoder, including SASL authentication mechanisms and X.500 certificate principal parsing paths.
The root cause is the absence of a bounds check comparing the declared content length against the available data in the input stream prior to memory allocation.

Comment 2 Jon Orris 2026-09-22 12:56:31 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8

Via RHSA-2026:70228 https://access.redhat.com/errata/RHSA-2026:70228

Comment 3 Jon Orris 2026-09-22 12:58:58 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 10

Via RHSA-2026:70230 https://access.redhat.com/errata/RHSA-2026:70230

Comment 4 Jon Orris 2026-09-22 13:01:04 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9

Via RHSA-2026:70229 https://access.redhat.com/errata/RHSA-2026:70229

Comment 5 Jon Orris 2026-09-22 15:36:06 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 8.1

Via RHSA-2026:70277 https://access.redhat.com/errata/RHSA-2026:70277


Note You need to log in before you can comment on or make changes to this bug.