CVE-2026-76646: Apache MyFaces: Denial of Service via Unbounded Request Parsing
A remote attacker could cause excessive resource consumption by supplying specially crafted request parameters, potentially resulting in a denial of service condition.
Older unsupported versions may also be affected.
Users are recommended to upgrade to versions 2.3.12, 2.3-next-M9, 3.0.4, 4.0.4, or 4.1.4, which fix this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache MyFacesto a version that resolves this vulnerability.Fixed in 2.3.12 - Upgrade
Upgrade
Apache MyFacesto a version that resolves this vulnerability.Fixed in 2.3-next-M9 - Upgrade
Upgrade
Apache MyFacesto a version that resolves this vulnerability.Fixed in 3.0.4 - Upgrade
Upgrade
Apache MyFacesto a version that resolves this vulnerability.Fixed in 4.0.4 - Upgrade
Upgrade
Apache MyFacesto a version that resolves this vulnerability.Fixed in 4.1.4
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
The attacker needs the ability to send specially crafted request parameters to an affected Apache MyFaces deployment. The described impact is excessive resource consumption that can lead to denial of service.
Which versions should be used to remediate the issue?
Upgrade to Apache MyFaces 2.3.12, 2.3-next-M9, 3.0.4, 4.0.4, or 4.1.4, as applicable to the deployment branch. Older unsupported versions may also be affected.