WildFly
Modular Jakarta EE application server for building and running Java applications
WildFly's first 41.x patch is a security release, with three IIOP CVEs closed at once
◆Recent moves
- 21d ago
WildFly 41.0.1 closes three IIOP CVEs and a Mojarra advisory
The first 41.x patch is primarily a security release: three IIOP CVEs — unauthenticated class loading, a missing-authentication NameService path, and a pre-auth listener denial of service — land alongside upgrades to RESTEasy, Mojarra, CXF, Netty and lz4-java that resolve further advisories. Functional fixes are narrow, covering cache listeners on resume and OIDC logout attribute parsing.
View source ↗ - 2mo ago
WildFly 41 promotes OIDC scope and request-object support
The 41.0.0 final promoted OIDC scope and request-object handling to default stability, the feature payload this patch line is now maintaining.
View source ↗ - 2mo ago
WildFly 41 Beta adds transactions during graceful shutdown
The 41 Beta allowed transactions to continue through graceful shutdown, an operational refinement typical of where WildFly spends its feature budget.
View source ↗ - 2mo ago
WildFly 40.0.1 moves container images to JDK 25, drops JDK 17
The previous line's patch release did the same job this one does — moving the runtime baseline forward rather than adding surface, in that case retiring JDK 17 from container images.
View source ↗ - 3mo ago
WildFly 40 lands Jakarta Pages 4.0 and WebSocket 2.2 in Preview
Jakarta Pages 4.0 and WebSocket 2.2 arrived in the Preview stability level, following the pattern of staging specification updates before promotion.
View source ↗ - 4mo ago
WildFly 40 Beta fixes an Elytron brute-force CVE
An earlier Beta carrying its own CVE fix in Elytron, confirming that security work reaches users through whichever release is next rather than waiting for a patch slot.
View source ↗