๐Ÿ” CVE Alert

CVE-2026-46581

UNKNOWN 0.0
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In Eclipse Mojarra versions 2.3 and following, URL handing in `DefaultFaceletFactory` does not properly sanitize and/or block remote URLs, allowing an attacker to specify a URL to a remote Facelet which will be included and processed as part of the normal request, with the privileges of the target server. This could allow access to restricted files such as `WEB-INF/web.xml` or `/etc/passwd`.

CWE CWE-22 CWE-94 CWE-641
Vendor eclipse foundation
Product eclipse mojarra
Published Aug 5, 2026
Stay Ahead of the Next One

Get instant alerts for eclipse foundation eclipse mojarra

Be the first to know when new unknown vulnerabilities affecting eclipse foundation eclipse mojarra are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Eclipse Foundation / Eclipse Mojarra
2.3 โ‰ค 5.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
gitlab.eclipse.org: https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/544 gitlab.eclipse.org: https://gitlab.eclipse.org/security/cve-assignment/-/work_items/160

Credits

Jason Lee