A flaw was found in Wildfly. A remote unauthenticated attacker can trigger OutOfMemoryError as CSIv2Util's GSS token decoder reads an attacker-controlled length field without bounds checking and attempts to allocate a byte array of that size.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-15567 is a remote denial-of-service vulnerability in Wildfly's CSIv2Util component that stems from improper input validation in GSS token processing. An unauthenticated attacker can exploit an unbounded length field in the GSS token decoder to trigger an OutOfMemoryError by requesting allocation of extremely large byte arrays. This vulnerability matters because Wildfly is widely deployed in enterprise environments as a Java EE application server, and the lack of authentication requirement means any network-connected attacker can initiate the attack. Organizations running vulnerable Wildfly instances face service disruption, resource starvation, and potential cascading failures across dependent systems.
While this CVE lacks direct MITRE ATT&CK technique mappings, Casky's 754 security skills leverage Claude's extended reasoning to correlate this memory exhaustion pattern with Resource Exhaustion (T1499) and Service Stop/Restart abuse scenarios. Practitioners using Casky would observe detection findings centered on abnormal memory allocation patterns, detection of oversized or malformed CSIv2/GSS authentication requests, and resource consumption spikes preceding service failures. The platform's skill engine would flag the absence of bounds checking in deserialization logic and highlight the critical control gap that authentication bypass creates. Security teams would see actionable insights linking network telemetry of failed authentication attempts with abnormal heap utilization, enabling them to distinguish legitimate traffic from exploitation attempts targeting this specific decoder vulnerability.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-15567. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation