ZeroHour
Product

Apache MyFaces

2 mentions in 7 days · 2 in 30 days · 2 total · first seen · last

Timeline

CVE-2026-68536: Apache MyFaces: Server-Side Request Forgery / Local File Inclusion Vulnerability

Apache MyFaces discloses moderate SSRF and local file inclusion vulnerability CVE-2026-68536 affecting all maintained 2.2 through 4.1 branches.

Apache MyFaces (org.apache.myfaces.core:myfaces-impl) disclosed CVE-2026-68536, a server-side request forgery and local file inclusion vulnerability rated moderate. Affected versions include the 2.2.*, 2.3.*, 3.0.*, 4.0.*, 4.1.* and 2.3-next-* branches. No exploitation details or patch status were provided in the disclosure.

CVE-2026-76646: Apache MyFaces: Denial of Service via Unbounded Request Parsing

Apache MyFaces fixes critical CVE-2026-76646, a remote denial-of-service flaw triggered by crafted request parameters across versions 2.2.0-4.1.3.

Apache MyFaces disclosed CVE-2026-76646, a critical denial-of-service vulnerability in which remote attackers can cause excessive resource consumption by supplying specially crafted request parameters. Affected versions span 2.2.0-2.2.15, 2.3.0-2.3.11, 3.0.0-3.0.3, 4.0.0-4.0.3, 4.1.0-4.1.3 and 2.3-next-*. The disclosure notes older versions may also be impacted.

Related CVEs

  • SSRF and Local File Inclusion in Apache MyFaces Core
    Apache MyFaces Core, the Apache implementation of JavaServer Faces (JSF) used by Java web applications, contains a Server-Side Request Forgery flaw (CWE-918) that can also lead to Local File Inclusion. An attacker can trigger it by sending a crafted request to an application running a vulnerable MyFaces Core version, causing the server to issue requests to attacker-chosen URLs and/or read local files. Depending on the hosting environment, this could expose internal services, cloud metadata endpoints, configuration files, or credentials. Any JSF-based application running MyFaces Core before the patched releases is affected, and older unsupported versions may also be vulnerable. No public proof-of-concept is known, the issue is not in CISA KEV, and no exploitation has been reported to date.
    · Apache MyFaces Core (2.3 branch) Versions prior to 2.3.12 (fixed in 2.3.12); older unsupported versions may also be affected · Apache MyFaces Core (2.3-next branch) Versions prior to 2.3-next-M9 (fixed in 2.3-next-M9)large
  • Denial of Service via Unbounded Request Parameter Parsing in Apache MyFaces
    Apache MyFaces, the open-source Java/Jakarta Faces implementation maintained by the Apache Software Foundation, contains an uncontrolled resource consumption flaw (CWE-400) in its request processing. A remote attacker can trigger the condition without authentication by supplying specially crafted request parameters, causing the application to consume excessive resources and potentially denying service to legitimate users. All supported MyFaces release branches prior to the fixed versions are affected, and older, unsupported versions may also be vulnerable. No public proof-of-concept, CISA KEV listing, or confirmed exploitation is known at this time.
    · Apache MyFaces 2.3.x prior to 2.3.12 · Apache MyFaces 2.3-next prior to 2.3-next-M9large

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.