Junglewise Threat Intelligence

OmniFaces multiple vulnerabilities in resource handling and push channels

Severity: high · CVSS 7.5 · Published 2026-07-24

Executive brief

OmniFaces, a utility library for JavaServer Faces (JSF), contains multiple vulnerabilities that can impact application stability and security. Attackers can trigger excessive memory consumption (denial of service) by forging resource identifiers, execute malicious scripts in a user's browser (XSS), or intercept real-time data updates intended for other users. These issues could lead to service outages, unauthorized data access, or full account compromise depending on the application's configuration.

Technical details

OmniFaces is affected by several distinct vulnerabilities. 1) CombinedResourceInfo lacks authenticity checks for path-derived IDs, allowing attackers to forge IDs that cause massive heap inflation and unbounded static cache growth (DoS). 2) The source-map handler lacks size or eviction bounds, leading to memory exhaustion. 3) o:hashParam fails to escape URL-fragment values before writing them to Ajax callback scripts, enabling Cross-Site Scripting (XSS). 4) The WebSocket push-channel implementation fails to bind handshakes to the current HTTP session, allowing replay of session-scoped channel IDs if the UUID is exposed. 5) Push-channel queues are unbounded and set idle timeouts to zero, creating a design weakness for resource exhaustion. Patches are available in versions 1.14.3, 2.7.33, 3.14.23, 4.7.12, and 5.4.2.

Affected products

  • omnifaces omnifaces < 1.14.3, >= 2.0.0, < 2.7.33, >= 3.0.0, < 3.14.23, >= 4.0.0, < 4.7.12, >= 5.0.0, < 5.4.2

Timeline

  • 2026-07-23: disclosed: Initial disclosure by Daniel Birtwhistle
  • 2026-07-24: advisory: GitHub Advisory published

References

Related threats