Fedora Account System
Red Hat Associate
Red Hat Customer
A resource exhaustion vulnerability exists in the DERDecoder class within org.wildfly.security:wildfly-elytron-asn1, where primitive type decoders (decodeOctetString(), decodeBitString(), decodeInteger(), etc.) allocate a byte[] array based on the declared length field of a DER-encoded input without validating it against the actual remaining bytes in the buffer. An attacker can craft a minimal 7-byte DER payload with an inflated length value, causing the decoder to attempt a multi-gigabyte heap allocation that exhausts JVM memory and triggers an OutOfMemoryError. This results in a remote denial-of-service condition against any service endpoint that processes untrusted DER/ASN.1 input through the affected decoder, including SASL authentication mechanisms and X.500 certificate principal parsing paths. The root cause is the absence of a bounds check comparing the declared content length against the available data in the input stream prior to memory allocation.
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8 Via RHSA-2026:70228 https://access.redhat.com/errata/RHSA-2026:70228
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 10 Via RHSA-2026:70230 https://access.redhat.com/errata/RHSA-2026:70230
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9 Via RHSA-2026:70229 https://access.redhat.com/errata/RHSA-2026:70229
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 8.1 Via RHSA-2026:70277 https://access.redhat.com/errata/RHSA-2026:70277