WildFly
Modular Jakarta EE application server for building and running Java applications
WildFly's quarterly train is really a stability ladder, and OIDC keeps climbing it
◆Recent moves
- 25d ago
WildFly 41 promotes OIDC scope and request-object support
The Final restates the feature set its Beta already carried two weeks earlier: OIDC scope attributes and request/request_uri parameters move to community stability, and the Maven plugin gains bootable-JAR packaging aimed at cloud deploys. It is another rung on the stability ladder rather than new capability.
View source ↗ - 1mo ago
WildFly 41 Beta adds transactions during graceful shutdown
The originating build of the 41 cycle, where the feature list actually lands before the Final repeats it. Transaction handling during graceful shutdown reaches default stability, as does OIDC logout and TLS on the JGroups TCP transport — all promotions of work that already existed at lower stability.
View source ↗ - 1mo ago
WildFly 40.0.1 moves container images to JDK 25, drops JDK 17
A patch release of dependency upgrades — Jackson, Netty, Infinispan, Galleon, HAL — with one operationally significant note attached: container images now target JDK 25 on UBI 10, and this is the last release publishing JDK 17 images. The runtime floor is moving even in a point release.
View source ↗ - 2mo ago
WildFly 40 lands Jakarta Pages 4.0 and WebSocket 2.2 in Preview
The EE 11 buildout continues in the Preview distribution, adding Jakarta Pages 4.0, WebSocket 2.2 and Authorization 3.0 alongside the first Preview-level OIDC logout support. This is the staging half of the ladder — the same items reappear later as promotions to default.
View source ↗ - 3mo ago
WildFly 40 Beta fixes an Elytron brute-force CVE
The 40 cycle's originating build, carrying the fix for CVE-2025-23368 (Elytron brute-force authentication) plus promotions of X-Forwarded rewriting and peer-based SSLContext delegation to default stability. As with the 41 pair, the Final two weeks later repeats this list.
View source ↗ - 6mo ago
WildFly 39.0.1 backports the Elytron brute-force CVE fix
A maintenance release on the 39 line whose one item worth acting on is the CVE-2025-23368 backport; the rest is clustering test flakiness and session-handling fixes. It shows the project maintaining the previous major while the next one stages features in Preview.
View source ↗