AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2019-3894

HIGH · CVSS 8.8 EPSS 1.51%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2019-05-03 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2019-3894
Severity
HIGH
CVSS
8.8
EPSS
1.51%

Original NVD Description

It was discovered that the ElytronManagedThread in Wildfly's Elytron subsystem in versions from 11 to 16 stores a SecurityIdentity to run the thread as. These threads do not necessarily terminate if the keep alive time has not expired. This could allow a shared thread to use the wrong security identity when executing.