{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/omnifaces-vulnerable--5.0.0--5.4.2/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-41883"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["omnifaces (vulnerable: \u003c 1.14.3)","omnifaces (vulnerable: \u003e= 2.0.0, \u003c 2.7.33)","omnifaces (vulnerable: \u003e= 3.0.0, \u003c 3.14.23)","omnifaces (vulnerable: \u003e= 4.0.0, \u003c 4.7.12)","omnifaces (vulnerable: \u003e= 5.0.0, \u003c 5.4.2)"],"_cs_severities":["high"],"_cs_tags":["web-vulnerability","ssrf","xss","dos","java","omnifaces","information-disclosure","session-hijacking"],"_cs_type":"advisory","_cs_vendors":["OmniFaces"],"content_html":"\u003cp\u003eThe OmniFaces project, a utility library for JavaServer Faces (JSF), published an advisory on July 24, 2026, detailing multiple high-severity vulnerabilities affecting various versions (specifically, prior to 1.14.3, 2.7.33, 3.14.23, 4.7.12, and 5.4.2). These issues include the exploitation of forged combined-resource IDs to bypass security boundaries, potentially leading to information disclosure of internal application resources or enabling server-side request forgery (SSRF)-like behavior through outbound connections. An XSS vulnerability allows client-side script execution due to improper escaping of JavaScript payloads from \u003ccode\u003eo:hashParam\u003c/code\u003e. Furthermore, session-scoped push channels are vulnerable to replay attacks, allowing unauthorized access to a victim's push messages. The presence of unbounded static caches and per-channel queues also introduces denial-of-service (DoS) risks through resource exhaustion, posing significant threats to data confidentiality, integrity, and availability. These issues are distinct from a prior CVE-2026-41883 fix, originating from unsigned combined IDs, missing decode/cache bounds, and improper input handling.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker crafts an HTTP request containing a forged \u003ccode\u003eCombinedResourceInfo\u003c/code\u003e ID or a URL with an unescaped JavaScript payload intended for \u003ccode\u003eo:hashParam\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe OmniFaces application processes the request, either accepting the forged ID due to missing authenticity checks or storing the unescaped JavaScript payload.\u003c/li\u003e\n\u003cli\u003eFor forged IDs, the application performs server-side fetches of internal resources (bypassing exclusion rules) or initiates outbound connections to attacker-specified hosts (SSRF-like behavior), potentially disclosing internal information.\u003c/li\u003e\n\u003cli\u003eFor the \u003ccode\u003eo:hashParam\u003c/code\u003e vulnerability, a victim's browser executes the unescaped JavaScript payload during a subsequent Ajax render, leading to client-side attacks.\u003c/li\u003e\n\u003cli\u003eAn attacker obtains a legitimate session-scoped push channel ID from a victim and reuses it to subscribe to the victim's push notifications, gaining unauthorized access to sensitive real-time data.\u003c/li\u003e\n\u003cli\u003eThrough repeated exploitation of unbounded caches (e.g., combined-resource IDs, source-map cache) or per-channel queues, the attacker causes resource exhaustion on the server, leading to application instability or denial of service for legitimate users.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerabilities allow for various severe impacts. Successful exploitation of forged combined-resource IDs can lead to sensitive information disclosure from internal application resources or enable server-side request forgery (SSRF)-like attacks, potentially allowing attackers to scan internal networks or interact with internal services. The cross-site scripting (XSS) vulnerability can result in client-side arbitrary code execution, enabling session hijacking, credential theft, or defacement of web pages for affected users. The session/view push-channel replay vulnerability permits unauthorized interception of real-time push messages intended for specific users, compromising data confidentiality. Additionally, multiple unbounded caches and queues create denial-of-service (DoS) opportunities, allowing attackers to exhaust server memory, CPU, or network resources, leading to application crashes or complete service unavailability.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade OmniFaces to a patched version (1.14.3, 2.7.33, 3.14.23, 4.7.12, or 5.4.2) immediately to mitigate all described vulnerabilities.\u003c/li\u003e\n\u003cli\u003eMonitor web server access logs for unusual request patterns, particularly those involving \u003ccode\u003eCombinedResourceInfo\u003c/code\u003e paths or \u003ccode\u003eo:hashParam\u003c/code\u003e with unusual or encoded characters.\u003c/li\u003e\n\u003cli\u003eImplement outbound network traffic monitoring to detect unexpected connections initiated by the application server, which could indicate SSRF-like activity from forged combined-resource IDs.\u003c/li\u003e\n\u003cli\u003eReview application logs for signs of resource exhaustion, such as excessive memory usage or frequent garbage collection events, potentially indicating denial-of-service attempts related to unbounded caches or queues.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-24T22:40:15Z","date_published":"2026-07-24T22:40:15Z","id":"https://feed.craftedsignal.io/briefs/2026-07-omnifaces-vulnerabilities/","summary":"Multiple vulnerabilities in OmniFaces versions prior to 1.14.3, 2.7.33, 3.14.23, 4.7.12, and 5.4.2 allow attackers to exploit forged combined-resource IDs leading to server-side request forgery (SSRF)-like behavior or information disclosure, achieve client-side arbitrary code execution via cross-site scripting (XSS) in `o:hashParam`, bypass session authentication for push channels resulting in unauthorized message interception, and cause denial-of-service (DoS) via unbounded caches.","title":"Multiple High-Severity Vulnerabilities in OmniFaces Library","url":"https://feed.craftedsignal.io/briefs/2026-07-omnifaces-vulnerabilities/"}],"language":"en","title":"CraftedSignal Threat Feed - Omnifaces (Vulnerable: \u003e= 5.0.0, \u003c 5.4.2)","version":"https://jsonfeed.org/version/1.1"}