{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/red-hat-build-of-quarkus/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.4,"id":"CVE-2026-19611"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Red Hat build of Apache Camel 4 for Quarkus 3","Red Hat build of Debezium 3","Red Hat Build of Keycloak","Red Hat build of Quarkus","Red Hat Data Grid 8","Red Hat JBoss Enterprise Application Platform 7"],"_cs_severities":["high"],"_cs_tags":["credential-access","vulnerability","middleware"],"_cs_type":"advisory","_cs_vendors":["Red Hat"],"content_html":"\u003cp\u003eA vulnerability (CVE-2026-19611) exists within the WildFly Elytron framework, which is utilized across multiple Red Hat middleware and security products. The flaw stems from the password hashing and verification processes performing Unicode NFKC normalization on input. This process collapses specific fullwidth characters into their ASCII equivalents. Because the system treats these transformed characters as identical to standard ASCII characters, an attacker can bypass the intended complexity of passwords that include non-ASCII characters. By leveraging an ASCII-only wordlist, an attacker can more effectively guess the password for a targeted account, significantly reducing the search space required for a successful brute-force or credential-stuffing attack. This vulnerability affects numerous enterprise products, including Keycloak, JBoss EAP, and Quarkus-based builds, and requires organizations to audit their authentication flows for impact.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability carries a CVSS 3.1 score of 7.4 (High). If successfully exploited, an unauthorized actor could gain access to protected services and data by brute-forcing credentials that were previously considered strong due to their inclusion of non-ASCII characters. The scope of impact extends to any environment using affected Red Hat middleware for authentication, potentially exposing enterprise-grade identity and access management systems.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eIdentify all instances of affected Red Hat products within the infrastructure (e.g., Keycloak, Data Grid 8, JBoss EAP 7).\u003c/li\u003e\n\u003cli\u003eApply security patches provided by Red Hat as soon as they become available for the affected \u003ccode\u003ewildfly-elytron-password-impl\u003c/code\u003e package.\u003c/li\u003e\n\u003cli\u003eImplement rate limiting and account lockout policies for all authentication endpoints to mitigate the risk of automated credential guessing attacks.\u003c/li\u003e\n\u003cli\u003eReview authentication logs for anomalous spikes in failed login attempts, particularly those originating from single IP addresses, which may indicate automated dictionary-based attempts targeting this vulnerability.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-20T19:18:38Z","date_published":"2026-08-20T19:18:38Z","id":"https://feed.craftedsignal.io/briefs/2026-08-wildfly-elytron-normalization/","summary":"A vulnerability in WildFly Elytron's password normalization logic allows attackers to bypass intended password character entropy, facilitating unauthorized access through dictionary-based credential guessing.","title":"Credential Guessing Vulnerability via WildFly Elytron Unicode Normalization","url":"https://feed.craftedsignal.io/briefs/2026-08-wildfly-elytron-normalization/"}],"language":"en","title":"CraftedSignal Threat Feed - Red Hat Build of Quarkus","version":"https://jsonfeed.org/version/1.1"}