Description
A remote attacker could cause excessive resource consumption by supplying specially crafted request parameters, potentially resulting in a denial of service condition.


Older unsupported versions may also be affected.

Users are recommended to upgrade to versions 2.3.12, 2.3-next-M9, 3.0.4, 4.0.4, or 4.1.4, which fix this issue.
Published: 2026-09-16
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch ASAP
AI Analysis

Impact

Apache MyFaces may process request parameters without bounding, letting a remote attacker supply crafted inputs that consume excessive server resources. This uncontrolled resource consumption can push the application into a denial of service state. The weakness is a classic case of CWE-400, where input validation fails to limit resource usage.

Affected Systems

The vulnerability affects Apache MyFaces releases older than 2.3.12, 2.3-next-M9, 3.0.4, 4.0.4, and 4.1.4, as well as any unsupported older versions. These are deployments that were built with the Apache Software Foundation’s MyFaces framework and have not applied the patch that restricts request size.

Risk and Exploitability

With a CVSS score of 7.5, the flaw carries a high severity rating, yet its EPSS score of less than 1% indicates a very low probability of exploitation in the wild. The vulnerability is not currently listed in the CISA KEV catalog. While no authentication is required, the attack vector is inferred to be remote, exploiting the web application’s ability to parse incoming HTTP requests. A successful exploit would exhaust critical application resources, resulting in a denial of service for legitimate users.

Generated by OpenCVE AI on September 18, 2026 at 01:36 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Apache MyFaces to at least version 2.3.12, 2.3-next-M9, 3.0.4, 4.0.4, or 4.1.4 where the request parsing limits have been implemented.
  • If an immediate upgrade is not possible, enforce strict request size limits or apply rate‑limiting to incoming traffic targeting the MyFaces components to reduce the risk of resource exhaustion.
  • Monitor application performance and logs for signs of abnormal request sizes or repeated denial of service symptoms, and alert on thresholds that could indicate an exploitation attempt.

Generated by OpenCVE AI on September 18, 2026 at 01:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 02:00:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache myfaces
Vendors & Products Apache
Apache myfaces

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
References

Wed, 16 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Description A remote attacker could cause excessive resource consumption by supplying specially crafted request parameters, potentially resulting in a denial of service condition. Older unsupported versions may also be affected. Users are recommended to upgrade to versions 2.3.12, 2.3-next-M9, 3.0.4, 4.0.4, or 4.1.4, which fix this issue.
Title Apache MyFaces: Denial of Service via Unbounded Request Parsing
Weaknesses CWE-400
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-09-17T19:13:59.659Z

Reserved: 2026-08-19T15:11:32.643Z

Link: CVE-2026-76646

cve-icon Vulnrichment

Updated: 2026-09-17T19:13:55.977Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T20:17:28.847

Modified: 2026-09-17T20:18:15.307

Link: CVE-2026-76646

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T01:45:16Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption