CVE-2026-19611CWE-173

CVE-2026-19611

High · published August 20, 2026

CVSS v3.1
7.4
EPSS
0%
Percentile
27.3
In the wild
Unconfirmed
What it is

A flaw was found in WildFly Elytron. Password hashing and verification normalize input with Unicode NFKC, which can collapse fullwidth characters to ASCII equivalents. A remote attacker can more easily guess affected passwords by using an ASCII-only dictionary against accounts whose passwords were intended to include those non-ASCII characters, leading to unauthorized access.

The record
Technical detail
CVSS v3.1
7.4 · HIGH
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS v4.0
Not supplied
EPSS
0.00345 · 27.3th percentile
Weakness
CWE-173 · Improper Handling of Alternate Encoding
Published
2026-08-20T20:17Z
References (2)
EPSS history
Timeline
  • 20 AUG 15:58Z
    Wildfly-elytron: org.wildfly.security/wildfly-elytron-password-impl: wildfly-elytron: password keyspace reduction via nfkc fullwidth folding
    cvelistv5