Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Org.omnifaces:omnifaces: OmniFaces: Forged combined-resource IDs and related output/push boundaries

0
High
Published: 07/24/2026 (07/24/2026, 22:35:27 UTC)
Source: GCVE Database
Product: org.omnifaces:omnifaces

Description

Multiple vulnerabilities exist in OmniFaces related to forged combined-resource IDs, unbounded caches, cross-site scripting via hashParam, session push-channel replay, and push idle-connection handling. Forged combined-resource IDs allow attackers to inflate resource usage and bypass resource boundaries. The source-map cache can grow unboundedly. The hashParam component can lead to JavaScript injection in Ajax callbacks. Session push channels are not properly bound to HTTP sessions, enabling replay of push messages. Push channel idle timeouts and client fanout lack proper limits. These issues affect multiple OmniFaces versions prior to fixed releases.

CVSS v3.1

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected software

Mavenghsa
org.omnifaces:omnifaces
Affected versions
<1.14.3
Mavenghsa
org.omnifaces:omnifaces
Affected versions
>=2.0.0 <2.7.33
Mavenghsa
org.omnifaces:omnifaces
Affected versions
>=3.0.0 <3.14.23
Mavenghsa
org.omnifaces:omnifaces
Affected versions
>=4.0.0 <4.7.12
Mavenghsa
org.omnifaces:omnifaces
Affected versions
>=5.0.0 <5.4.2

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/25/2026, 23:49:34 UTC

Technical Analysis

This vulnerability report details several issues in OmniFaces involving forged combined-resource IDs that lack authenticity checks, allowing attackers to inflate resource usage and bypass resource boundaries, including CDN wildcard mappings and inner resource access. The source-map cache grows unboundedly with missing eviction. The o:hashParam component writes unescaped JavaScript payloads into Ajax callbacks, enabling XSS. WebSocket push channels do not bind handshakes to HTTP sessions, allowing replay of victim push messages after token exposure. Push channel idle timeouts are set to zero and sessions accumulate in unbounded queues, causing resource management concerns. The report suggests fixes including authenticating combined IDs, bounding caches, escaping hashParam output, binding push subscriptions to sessions, and adding configurable idle timeouts and channel limits. Affected versions span multiple major releases prior to specific fixed versions.

Potential Impact

The forged combined-resource ID vulnerability can cause excessive memory usage and bypass resource access restrictions, potentially exposing raw resource content and causing server-side fetches to attacker-controlled hosts. The unbounded source-map cache can lead to increased memory consumption. The hashParam XSS vulnerability allows injection of arbitrary JavaScript in Ajax callbacks, leading to client-side code execution. The session/view push-channel replay flaw permits an attacker with a victim's channel ID to receive push messages intended for that victim, violating session isolation. The push idle-connection and fanout design can cause resource exhaustion due to unbounded session queues and zero idle timeouts. These impacts can degrade service availability and compromise client security.

Mitigation Recommendations

No official patch links are provided; patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Suggested mitigations include authenticating combined-resource IDs with a per-deployment secret, limiting inflated output size, bounding or evicting caches including the combined-resource and source-map caches, rejecting attacker-selected inner resources at serve time, deriving dynamic resource origins from trusted configuration rather than untrusted Host headers, applying JavaScript-string and CDATA-safe encoding to hashParam callback values, binding WebSocket push subscriptions to the owning HTTP session or authenticated principal, and configuring finite idle timeouts and per-channel client limits. Operators should monitor vendor advisories for official fixes and apply them when available.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-fp43-vj7g-pg92
Osv Schema Version
1.4.0
Aliases
[]
Ecosystems
["Maven"]
Database Specific Severity
HIGH
Cvss Version
3.1

Threat ID: 6a6542199c2644c7f8087e45

Added to database: 07/25/2026, 23:09:13 UTC

Last enriched: 07/25/2026, 23:49:34 UTC

Last updated: 07/26/2026, 03:45:44 UTC

Views: 4

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses