Threats Tagged 'ghsa-fp43-vj7g-pg92'
View all threats tagged with 'ghsa-fp43-vj7g-pg92'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'ghsa-fp43-vj7g-pg92'
Click on any threat for detailed analysis and mitigation recommendations
Org.omnifaces:omnifaces: OmniFaces: Forged combined-resource IDs and related output/push boundaries 0 Multiple vulnerabilities exist in OmniFaces related to forged combined-resource IDs, unbounded caches, cross-site scripting via hashParam, session push-channel replay, and push idle-connection handling. Forged combined-resource IDs allow attackers to inflate resource usage and bypass resource boundaries. The source-map cache can grow unboundedly. The hashParam component can lead to JavaScript injection in Ajax callbacks. Session push channels are not properly bound to HTTP sessions, enabling replay of push messages. Push channel idle timeouts and client fanout lack proper limits. These issues affect multiple OmniFaces versions prior to fixed releases. Join the discussion | GCVE Database | 07/24/2026, 22:35:27 UTC Added: 07/25/2026, 23:09:13 UTC |
Showing 1 to 1 of 1 result