云虫漏洞库

CVE-2026-19611 - A flaw was found in WildFly Elytron. Password hashing and verification normalize input with Unicode NFKC, which can collapse fullwidth characters to ASCII equivalents. A remote attacker can more easily guess affected passwords by using an ASCII-only dictionary against accounts whose passwords were intended to include those non-ASCII characters, leading to unauthorized access. - 漏洞详情

漏洞编号:CVE-2026-19611

风险等级:高危

漏洞来源:CVE

CVE 编号:CVE-2026-19611

CNNVD 编号:-

厂商/产品:- / -

影响范围:-

CWE:CWE-173

发布/更新时间:2026-08-20 / 2026-08-28

漏洞描述

A flaw was found in WildFly Elytron. Password hashing and verification normalize input with Unicode NFKC, which can collapse fullwidth characters to ASCII equivalents. A remote attacker can more easily guess affected passwords by using an ASCII-only dictionary against accounts whose passwords were intended to include those non-ASCII characters, leading to unauthorized access.

相关链接

相关漏洞

« 返回首页