Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-15567

Опубликовано: 11 авг. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

A flaw was found in Wildfly. A remote unauthenticated attacker can trigger OutOfMemoryError as CSIv2Util's GSS token decoder reads an attacker-controlled length field without bounds checking and attempts to allocate a byte array of that size.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Fuse 7wildfly-iiop-openjdkOut of support scope
Red Hat JBoss Enterprise Application Platform 8wildfly-iiop-openjdkAffected
Red Hat JBoss Enterprise Application Platform Expansion Packwildfly-iiop-openjdkNot affected
Red Hat Single Sign-On 7wildfly-iiop-openjdkOut of support scope
Red Hat JBoss Enterprise Application Platform 7.4.25wildfly-iiop-openjdkFixedRHSA-2026:5380611.08.2026

Показывать по

Дополнительная информация

Статус:

Important
https://bugzilla.redhat.com/show_bug.cgi?id=2491620wildfly: wildfly-iiop: wildfly-jacorb: Wildfly: Pre-auth denial of service on the IIOP listener

EPSS

Процентиль: 36%
0.00436
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
7 дней назад

A flaw was found in Wildfly. A remote unauthenticated attacker can trigger OutOfMemoryError as CSIv2Util's GSS token decoder reads an attacker-controlled length field without bounds checking and attempts to allocate a byte array of that size.

CVSS3: 7.5
debian
7 дней назад

A flaw was found in Wildfly. A remote unauthenticated attacker can tri ...

CVSS3: 7.5
github
7 дней назад

A flaw was found in Wildfly. A remote unauthenticated attacker can trigger OutOfMemoryError as CSIv2Util's GSS token decoder reads an attacker-controlled length field without bounds checking and attempts to allocate a byte array of that size.

EPSS

Процентиль: 36%
0.00436
Низкий

7.5 High

CVSS3