Apache MyFaces discloses critical DoS flaw (CVE-2026-76646) and moderate SSRF/LFI flaw (CVE-2026-68536)
On 2026-09-16 the Apache MyFaces team disclosed CVE-2026-76646, a critical remote denial-of-service vulnerability caused by unbounded request parsing affecting versions 2.2.0 through 4.1.3 (older versions may also be affected), and CVE-2026-68536, a moderate…
Apache MyFaces published two vulnerability disclosures on oss-security on 2026-09-16. The first, CVE-2026-76646, is a critical remote denial-of-service flaw in which attackers can supply specially crafted request parameters to trigger excessive resource consumption; the root cause is unbounded request parsing. Affected versions are 2.2.0-2.2.15, 2.3.0-2.3.11, 3.0.0-3.0.3, 4.0.0-4.0.3, 4.1.0-4.1.3 and 2.3-next-*, and the disclosure notes older versions may also be impacted. The disclosure describes this CVE as fixed. The second, CVE-2026-68536, is a moderate-severity server-side request forgery and local file inclusion vulnerability in the MyFaces JSF implementation (org.apache.myfaces.core:myfaces-impl), affecting the maintained 2.2.*, 2.3.*, 3.0.*, 4.0.*, 4.1.* and 2.3-next-* branches. The CVE-2026-68536 disclosure provided no exploitation details or patch status, and no exploitation has been reported for either vulnerability.
- CVE-2026-76646: critical remote denial-of-service vulnerability in Apache MyFaces; crafted request parameters cause excessive resource consumption via unbounded request parsing.
- CVE-2026-76646 affects versions 2.2.0-2.2.15, 2.3.0-2.3.11, 3.0.0-3.0.3, 4.0.0-4.0.3, 4.1.0-4.1.3 and 2.3-next-*; older versions may also be affected.
- CVE-2026-76646 is rated critical by Apache, and the disclosure indicates the flaw is fixed.
- CVE-2026-68536: moderate-severity server-side request forgery and local file inclusion vulnerability in org.apache.myfaces.core:myfaces-impl.
- CVE-2026-68536 affects all maintained branches: 2.2.*, 2.3.*, 3.0.*, 4.0.*, 4.1.* and 2.3-next-*.
- No exploitation has been reported for either CVE; the CVE-2026-68536 disclosure provided no exploitation details or patch status.
- Both disclosures were published on oss-security on 2026-09-16.
Coverage timelineoldest first · each row is one article
- · 1h agoCVE-2026-76646: Apache MyFaces: Denial of Service via Unbounded Request Parsing
oss-security· 45
Apache MyFaces fixes critical CVE-2026-76646, a remote denial-of-service flaw triggered by crafted request parameters across versions 2.2.0-4.1.3.
- · 1h agoCVE-2026-68536: Apache MyFaces: Server-Side Request Forgery / Local File Inclusion Vulnerability
oss-security· 35
Apache MyFaces discloses moderate SSRF and local file inclusion vulnerability CVE-2026-68536 affecting all maintained 2.2 through 4.1 branches.
Vulnerabilities in this storyAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-68536 | NVD description · AI analysis pending | — | — | — | — | — | |
| CVE-2026-76646 | NVD description · AI analysis pending | — | — | — | — | — |