Executive brief
OmniFaces is a utility library used in Java-based web applications to simplify common development tasks. A vulnerability in how the library handles external content delivery networks (CDNs) allows an attacker to execute malicious code on the server. This could lead to a complete system takeover, unauthorized access to sensitive customer data, or service disruptions.
Technical details
A server-side Expression Language (EL) injection vulnerability exists in OmniFaces when using the CDNResourceHandler with wildcard CDN mappings (e.g., libraryName:*=https://cdn.example.com/*). The root cause is the improper neutralization of user-supplied resource names in request URLs, which are subsequently evaluated as EL expressions by the server. An unauthenticated remote attacker can exploit this by crafting a URL containing a malicious EL expression. Depending on the EL implementation and available objects, this can result in Remote Code Execution (RCE), information disclosure, or Denial of Service (DoS). The issue is patched in versions 1.14.2, 2.7.32, 3.14.16, 4.7.5, and 5.2.3; users can also mitigate the risk by replacing wildcard mappings with explicit resource-to-URL mappings.
Affected products
- OmniFaces OmniFaces < 1.14.2, < 2.7.32, < 3.14.16, < 4.7.5, < 5.2.3
Timeline
- 2026-04-15: advisory: GitHub Security Advisory published
- 2026-05-08: disclosed: CVE published to NVD