CVE-2026-15567: Red Hat Fuse 7
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
A flaw was found in Wildfly. A remote unauthenticated attacker can trigger OutOfMemoryError as CSIv2Util's GSS token decoder reads an attacker-controlled length field without bounds checking and attempts to allocate a byte array of that size.
Affected products
- Red Hat Red Hat Fuse 7
- Red Hat Red Hat JBoss Enterprise Application Platform 7
- Red Hat Red Hat JBoss Enterprise Application Platform 7.4.25: before 7.4.25.GA-redhat-00001 (fixed in 7.4.25.GA-redhat-00001)
- Red Hat Red Hat JBoss Enterprise Application Platform 7.4 Els On Rhel 7: before 0:2.16.0-22.redhat_00057.1.el7eap (fixed in 0:2.16.0-22.redhat_00057.1.el7eap); before 0:2.3.14-11.SP11_redhat_00001.1.el7eap (fixed in 0:2.3.14-11.SP11_redhat_00001.1.el7eap); before 0:1.5.26-2.Final_redhat_00001.1.el7eap (fixed in 0:1.5.26-2.Final_redhat_00001.1.el7eap); before 0:2.18.8-1.redhat_00003.1.el7eap (fixed in 0:2.18.8-1.redhat_00003.1.el7eap); before 0:5.0.31-3.SP2_redhat_00001.1.el7eap (fixed in 0:5.0.31-3.SP2_redhat_00001.1.el7eap); before 0:1.10.0-46.Final_redhat_00044.1.el7eap (fixed in 0:1.10.0-46.Final_redhat_00044.1.el7eap); …
- Red Hat Red Hat JBoss Enterprise Application Platform 7.4 Els On Rhel 8: before 0:2.16.0-22.redhat_00057.1.el8eap (fixed in 0:2.16.0-22.redhat_00057.1.el8eap); before 0:2.3.14-11.SP11_redhat_00001.1.el8eap (fixed in 0:2.3.14-11.SP11_redhat_00001.1.el8eap); before 0:1.5.26-2.Final_redhat_00001.1.el8eap (fixed in 0:1.5.26-2.Final_redhat_00001.1.el8eap); before 0:2.18.8-1.redhat_00003.1.el8eap (fixed in 0:2.18.8-1.redhat_00003.1.el8eap); before 0:5.0.31-3.SP2_redhat_00001.1.el8eap (fixed in 0:5.0.31-3.SP2_redhat_00001.1.el8eap); before 0:1.10.0-46.Final_redhat_00044.1.el8eap (fixed in 0:1.10.0-46.Final_redhat_00044.1.el8eap); …
- Red Hat Red Hat JBoss Enterprise Application Platform 7.4 Els On Rhel 9: before 0:2.16.0-22.redhat_00057.1.el9eap (fixed in 0:2.16.0-22.redhat_00057.1.el9eap); before 0:2.3.14-11.SP11_redhat_00001.1.el9eap (fixed in 0:2.3.14-11.SP11_redhat_00001.1.el9eap); before 0:1.5.26-2.Final_redhat_00001.1.el9eap (fixed in 0:1.5.26-2.Final_redhat_00001.1.el9eap); before 0:2.18.8-1.redhat_00003.1.el9eap (fixed in 0:2.18.8-1.redhat_00003.1.el9eap); before 0:5.0.31-3.SP2_redhat_00001.1.el9eap (fixed in 0:5.0.31-3.SP2_redhat_00001.1.el9eap); before 0:1.10.0-46.Final_redhat_00044.1.el9eap (fixed in 0:1.10.0-46.Final_redhat_00044.1.el9eap); …
- Red Hat Red Hat JBoss Enterprise Application Platform 8.1 For Rhel 10: before 0:2.40.0-8.redhat_00024.1.el10eap (fixed in 0:2.40.0-8.redhat_00024.1.el10eap); before 0:4.1.7-1.SP1_redhat_00001.1.el10eap (fixed in 0:4.1.7-1.SP1_redhat_00001.1.el10eap); before 0:2.0.5-1.Final_redhat_00001.1.el10eap (fixed in 0:2.0.5-1.Final_redhat_00001.1.el10eap); before 0:1.85.0-1.redhat_00001.1.el10eap (fixed in 0:1.85.0-1.redhat_00001.1.el10eap); before 0:1.2.7-1.redhat_00002.1.el10eap (fixed in 0:1.2.7-1.redhat_00002.1.el10eap); before 0:801.8.0-1.GA_redhat_00001.1.el10eap (fixed in 0:801.8.0-1.GA_redhat_00001.1.el10eap); …
- Red Hat Red Hat JBoss Enterprise Application Platform 8.1 For Rhel 8: before 0:2.40.0-8.redhat_00024.1.el8eap (fixed in 0:2.40.0-8.redhat_00024.1.el8eap); before 0:4.1.7-1.SP1_redhat_00001.1.el8eap (fixed in 0:4.1.7-1.SP1_redhat_00001.1.el8eap); before 0:2.0.5-1.Final_redhat_00001.1.el8eap (fixed in 0:2.0.5-1.Final_redhat_00001.1.el8eap); before 0:1.85.0-1.redhat_00001.1.el8eap (fixed in 0:1.85.0-1.redhat_00001.1.el8eap); before 0:1.2.7-1.redhat_00002.1.el8eap (fixed in 0:1.2.7-1.redhat_00002.1.el8eap); before 0:801.8.0-1.GA_redhat_00001.1.el8eap (fixed in 0:801.8.0-1.GA_redhat_00001.1.el8eap); …
- Red Hat Red Hat JBoss Enterprise Application Platform 8.1 For Rhel 9: before 0:2.40.0-8.redhat_00024.1.el9eap (fixed in 0:2.40.0-8.redhat_00024.1.el9eap); before 0:4.1.7-1.SP1_redhat_00001.1.el9eap (fixed in 0:4.1.7-1.SP1_redhat_00001.1.el9eap); before 0:2.0.5-1.Final_redhat_00001.1.el9eap (fixed in 0:2.0.5-1.Final_redhat_00001.1.el9eap); before 0:1.85.0-1.redhat_00001.1.el9eap (fixed in 0:1.85.0-1.redhat_00001.1.el9eap); before 0:1.2.7-1.redhat_00002.1.el9eap (fixed in 0:1.2.7-1.redhat_00002.1.el9eap); before 0:801.8.0-1.GA_redhat_00001.1.el9eap (fixed in 0:801.8.0-1.GA_redhat_00001.1.el9eap); …
- Red Hat Red Hat JBoss Enterprise Application Platform Expansion Pack
- Red Hat Red Hat Single Sign-On 7
Published 2026-08-11. Last modified 2026-09-25.