CVE-2026-46581
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
In Eclipse Mojarra versions 2.3 and following, URL handing in `DefaultFaceletFactory` does not properly sanitize and/or block remote URLs, allowing an attacker to specify a URL to a remote Facelet which will be included and processed as part of the normal request, with the privileges of the target server. This could allow access to restricted files such as `WEB-INF/web.xml` or `/etc/passwd`.
| CWE | CWE-22 CWE-94 CWE-641 |
| Vendor | eclipse foundation |
| Product | eclipse mojarra |
| Published | Aug 5, 2026 |
Stay Ahead of the Next One
Get instant alerts for eclipse foundation eclipse mojarra
Be the first to know when new unknown vulnerabilities affecting eclipse foundation eclipse mojarra are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Eclipse Foundation / Eclipse Mojarra
2.3 โค 5.0
References
Credits
Jason Lee