Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-vp6r-9m58-5xv8 | OmniFaces: EL injection via crafted resource name in wildcard CDN mapping |
Sun, 10 May 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Omnifaces
Omnifaces omnifaces |
|
| Vendors & Products |
Omnifaces
Omnifaces omnifaces |
Fri, 08 May 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 08 May 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OmniFaces is a utility library for Faces. Prior to versions 1.14.2, 2.7.32, 3.14.16, 4.7.5, and 5.2.3, there is a server-side EL injection leading to Remote Code Execution (RCE). This affects applications that use CDNResourceHandler with a wildcard CDN mapping (e.g. libraryName:*=https://cdn.example.com/*). An attacker can craft a resource request URL containing an EL expression in the resource name, which is evaluated server-side. This issue has been patched in versions 1.14.2, 2.7.32, 3.14.16, 4.7.5, and 5.2.3. | |
| Title | OmniFaces: EL injection via crafted resource name in wildcard CDN mapping | |
| Weaknesses | CWE-917 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-08T19:40:03.022Z
Reserved: 2026-04-22T15:11:54.670Z
Link: CVE-2026-41883
Updated: 2026-05-08T19:39:33.976Z
Status : Deferred
Published: 2026-05-08T16:16:11.760
Modified: 2026-05-13T16:34:42.677
Link: CVE-2026-41883
No data.
OpenCVE Enrichment
Updated: 2026-05-10T21:25:09Z
Github GHSA