CVE-2025-2251

Executive Summary

CVE-2025-2251 exposes WildFly and JBoss EAP to unauthenticated remote code execution via deserialization of untrusted data in the EJB remote invocation mechanism. Attackers can send crafted serialized objects processed by JBoss Marshalling, triggering arbitrary code execution on the target server. The flaw affects all versions of WildFly and JBoss EAP that use the default EJB remote interface, with no mitigations or patches currently available. Immediate remediation requires updating to patched releases or disabling the vulnerable EJB remote service.


Authoritative CVE Metadata - CVSS Base Score: 6.2 (MEDIUM) - Published: 2025-04-07T14:15:24.400 - Last Modified: 2026-08-19T01:16:54.890

Original Description: A security flaw exists in WildFly and JBoss Enterprise Application Platform (EAP) within the Enterprise JavaBeans (EJB) remote invocation mechanism. This vulnerability stems from untrusted data deserialization handled by JBoss Marshalling. This flaw allows an attacker to send a specially crafted serialized object, leading to remote code execution without requiring authentication.

"Love at first sight is easy to understand; its when two people have been looking at each other for a lifetime that it becomes a miracle."

— Amy Bloom
Source: NVD