wildfly_core vulnerabilities
CVEs whose affected-version data names the wildfly_core package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2025-23368High· 8.1A flaw was found in Wildfly Elytron integration
A flaw was found in Wildfly Elytron integration. The component does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it more susceptible to brute force attacks via CLI.
▾ Twilightredhat · wildfly_coreEPSS 0.87%via NVD
CVE-2023-4061Medium· 6.5A flaw was found in wildfly-core
A flaw was found in wildfly-core. A management user could use the resolve-expression in the HAL Interface to read possible sensitive information from the Wildfly system. This issue could allow a malicious user to access the system and ob…
▾ Sunlitredhat · jboss_enterprise_application_platformEPSS 0.83%via NVD