CVE-2026-76646
Apache Software Foundation · Apache MyFaces
A vulnerability in Apache MyFaces allows unauthenticated remote attackers to cause a denial of service via crafted request parameters leading to uncontrolled resource consumption.
Executive summary
A high-severity denial of service vulnerability in Apache MyFaces allows unauthenticated remote attackers to crash systems by exhausting resources through malicious request parameters.
Vulnerability
This is an uncontrolled resource consumption flaw (CWE-400) where an unauthenticated remote attacker can supply specially crafted request parameters to trigger excessive resource usage.
Business impact
Successful exploitation of this vulnerability results in a denial of service, rendering the Apache MyFaces application unavailable to legitimate users. Given the CVSS score of 7.5 and the unauthenticated nature of the attack vector, this poses a significant risk to service continuity and operational uptime. Organizations relying on MyFaces for critical business processes should prioritize this update to prevent potential service outages.
Remediation
Immediate Action: Upgrade to versions 2.3.12, 2.3-next-M9, 3.0.4, 4.0.4, or 4.1.4 as recommended by the vendor to address the underlying resource handling flaw.
Proactive Monitoring: Monitor server resource utilization, including CPU and memory metrics, and review access logs for unusually large or repetitive request patterns targeting application parameters.
Compensating Controls: Deploy a Web Application Firewall to filter or rate-limit suspicious incoming traffic and malformed request parameters that may attempt to trigger resource exhaustion.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
The severity of this vulnerability is high due to the ease of exploitation and the potential for complete service disruption. IT administrators must prioritize patching the affected instances of Apache MyFaces to the corrected versions immediately to eliminate the risk of denial of service attacks.
More Apache Software Foundation CVEs
History
CVE Brief tracked this CVE 2 days before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 7.5 (3.1)
- Analyst report written
Sources
Originally found and disclosed by n0mi1k, per the CVE Program record.