ZeroHour
oss-securitypublished ()ingested
Part of a story covered by 2 sources: “Apache MyFaces discloses critical DoS flaw (CVE-2026-76646) and moderate SSRF/LFI flaw (CVE-2026-68536)” — merged summary and timeline →

CVE-2026-76646: Apache MyFaces: Denial of Service via Unbounded Request Parsing

AI summary · glm-5.3-flash

Apache MyFaces fixes critical CVE-2026-76646, a remote denial-of-service flaw triggered by crafted request parameters across versions 2.2.0-4.1.3.

Apache MyFaces disclosed CVE-2026-76646, a critical denial-of-service vulnerability in which remote attackers can cause excessive resource consumption by supplying specially crafted request parameters. Affected versions span 2.2.0-2.2.15, 2.3.0-2.3.11, 3.0.0-3.0.3, 4.0.0-4.0.3, 4.1.0-4.1.3 and 2.3-next-*. The disclosure notes older versions may also be impacted.

  • Remote attackers can trigger excessive resource consumption and denial of service via crafted request parameters.
  • Severity rated critical by Apache; affects MyFaces releases from 2.2.0 through 4.1.3.
  • Older versions may also be affected; unbounded request parsing is the root cause.
VendorsApache

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-76646

NVD description · AI analysis pending
Full article

Posted by Volodymyr Siedlecki on Sep 16 Severity: critical Affected versions: - Apache MyFaces 2.2.0 through 2.2.15 - Apache MyFaces 2.3.0 through 2.3.11 - Apache MyFaces 3.0.0 through 3.0.3 - Apache MyFaces 4.0.0 through 4.0.3 - Apache MyFaces 4.1.0 through 4.1.3 - Apache MyFaces 2.3-next-* Description: A remote attacker could cause excessive resource consumption by supplying specially crafted request parameters, potentially resulting in a denial of service condition. Older...

This source does not provide full text. Read it at seclists.org.