ZeroHour
Story · 1 source · 2 articlesfirst updated ()

Apache MyFaces discloses critical DoS flaw (CVE-2026-76646) and moderate SSRF/LFI flaw (CVE-2026-68536)

What's new: First merged summary for this story: two Apache MyFaces vulnerabilities (CVE-2026-76646, critical DoS; CVE-2026-68536, moderate SSRF/LFI) were disclosed the same day, 2026-09-16, covering releases from the 2.2 branch through 4.1.3.
Merged summary · glm-5.3-flash · rewritten as coverage arrives

On 2026-09-16 the Apache MyFaces team disclosed CVE-2026-76646, a critical remote denial-of-service vulnerability caused by unbounded request parsing affecting versions 2.2.0 through 4.1.3 (older versions may also be affected), and CVE-2026-68536, a moderate…

Apache MyFaces published two vulnerability disclosures on oss-security on 2026-09-16. The first, CVE-2026-76646, is a critical remote denial-of-service flaw in which attackers can supply specially crafted request parameters to trigger excessive resource consumption; the root cause is unbounded request parsing. Affected versions are 2.2.0-2.2.15, 2.3.0-2.3.11, 3.0.0-3.0.3, 4.0.0-4.0.3, 4.1.0-4.1.3 and 2.3-next-*, and the disclosure notes older versions may also be impacted. The disclosure describes this CVE as fixed. The second, CVE-2026-68536, is a moderate-severity server-side request forgery and local file inclusion vulnerability in the MyFaces JSF implementation (org.apache.myfaces.core:myfaces-impl), affecting the maintained 2.2.*, 2.3.*, 3.0.*, 4.0.*, 4.1.* and 2.3-next-* branches. The CVE-2026-68536 disclosure provided no exploitation details or patch status, and no exploitation has been reported for either vulnerability.

  • CVE-2026-76646: critical remote denial-of-service vulnerability in Apache MyFaces; crafted request parameters cause excessive resource consumption via unbounded request parsing.
  • CVE-2026-76646 affects versions 2.2.0-2.2.15, 2.3.0-2.3.11, 3.0.0-3.0.3, 4.0.0-4.0.3, 4.1.0-4.1.3 and 2.3-next-*; older versions may also be affected.
  • CVE-2026-76646 is rated critical by Apache, and the disclosure indicates the flaw is fixed.
  • CVE-2026-68536: moderate-severity server-side request forgery and local file inclusion vulnerability in org.apache.myfaces.core:myfaces-impl.
  • CVE-2026-68536 affects all maintained branches: 2.2.*, 2.3.*, 3.0.*, 4.0.*, 4.1.* and 2.3-next-*.
  • No exploitation has been reported for either CVE; the CVE-2026-68536 disclosure provided no exploitation details or patch status.
  • Both disclosures were published on oss-security on 2026-09-16.
VendorsApache

Coverage timeline

  1. · 1h ago
    oss-security· 45
    CVE-2026-76646: Apache MyFaces: Denial of Service via Unbounded Request Parsing

    Apache MyFaces fixes critical CVE-2026-76646, a remote denial-of-service flaw triggered by crafted request parameters across versions 2.2.0-4.1.3.

  2. · 1h ago
    oss-security· 35
    CVE-2026-68536: Apache MyFaces: Server-Side Request Forgery / Local File Inclusion Vulnerability

    Apache MyFaces discloses moderate SSRF and local file inclusion vulnerability CVE-2026-68536 affecting all maintained 2.2 through 4.1 branches.

Vulnerabilities in this storyAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-68536

NVD description · AI analysis pending
CVE-2026-76646

NVD description · AI analysis pending