What is CVE-2026-15567?
A critical vulnerability was found in Wildfly (CVE-2026-15567). A remote unauthenticated attacker can trigger an OutOfMemoryError because CSIv2Util's GSS token decoder reads an attacker-controlled length field without bounds checking and attempts to allocate a byte array of that size. This may cause a denial of service; applying Wildfly updates is recommended.
Azərbaycanca: Wildfly serverində kritik boşluq aşkarlanıb (CVE-2026-15567). Uzaqdan autentifikasiya olunmamış hücumçu, CSIv2Util-in GSS token dekoderində sərhəd yoxlaması olmadığı üçün nəzarət etdiyi ölçü sahəsi ilə OutOfMemoryError yarada bilər. Bu, serverin əlçatmaz olmasına səbəb ola bilər; Wildfly yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-20
FAQ2
What can an attacker exploiting CVE-2026-15567 cause on a Wildfly server?
A remote unauthenticated attacker can trigger an OutOfMemoryError by exploiting the flaw in CSIv2Util's GSS token decoder, potentially causing a denial of service.
What is the root cause of CVE-2026-15567?
The vulnerability exists because CSIv2Util's GSS token decoder reads an attacker-controlled length field without bounds checking and attempts to allocate a byte array of that size.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.