CVE-2026-76646 PUBLISHED

Apache MyFaces: Denial of Service via Unbounded Request Parsing

Assigner: apache
Reserved: 19.08.2026 Published: 16.09.2026 Updated: 16.09.2026

A remote attacker could cause excessive resource consumption by supplying specially crafted request parameters, potentially resulting in a denial of service condition.

Older unsupported versions may also be affected.

Users are recommended to upgrade to versions 2.3.12, 2.3-next-M9, 3.0.4, 4.0.4, or 4.1.4, which fix this issue.

Product Status

Vendor Apache Software Foundation
Product Apache MyFaces
Versions Default: unaffected
  • affected from 2.2.0-beta to 2.2.15 (incl.)
  • Version 2.3.0 is affected
  • affected from 2.3-next-M1 to 2.3-next-M8 (incl.)
  • affected from 2.3.1 to 2.3.11 (incl.)
  • affected from 3.0.0 to 3.0.3 (incl.)
  • affected from 4.0.0 to 4.0.3 (incl.)
  • affected from 4.1.0 to 4.1.3 (incl.)

Credits

  • n0mi1k reporter

References

Problem Types

  • CWE-400 Uncontrolled Resource Consumption CWE