HIGH
CVE-2026-15567
CVSS
7.5
Description
A flaw was found in Wildfly. A remote unauthenticated attacker can trigger OutOfMemoryError as CSIv2Util's GSS token decoder reads an attacker-controlled length field without bounds checking and attempts to allocate a byte array of that size.
Weakness (CWE)
CWE-789
EPSS Score
0.47%
Probability of exploitation in next 30 days
39.4th percentile
References
https://access.redhat.com/errata/RHSA-2026:53644
https://access.redhat.com/errata/RHSA-2026:53645
https://access.redhat.com/errata/RHSA-2026:53646
https://access.redhat.com/errata/RHSA-2026:53806
https://access.redhat.com/security/cve/CVE-2026-15567
https://bugzilla.redhat.com/show_bug.cgi?id=2491620
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.