#VU123117 Improper restriction of excessive authentication attempts in Wildfly Core - CVE-2025-23368
Published: February 22, 2026
Wildfly Core
Red Hat Inc.
Description
The vulnerability allows a remote attacker to perform a brute-force attack.
The vulnerability exists within the Wildfly Elytron integration due to the component does not prevent multiple failed authentication attempts within a short time frame. A remote attacker can perform a brute-force attack and gain unauthorized access to the application.