CVE-2026-46581

NameCVE-2026-46581
DescriptionIn Eclipse Mojarra versions 2.3 and following, URL handing in `DefaultFaceletFactory` does not properly sanitize and/or block remote URLs, allowing an attacker to specify a URL to a remote Facelet which will be included and processed as part of the normal request, with the privileges of the target server. This could allow access to restricted files such as `WEB-INF/web.xml` or `/etc/passwd`.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
mojarra (PTS)forky, sid, bookworm, bullseye, trixie2.2.8-6fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
mojarrasource(unstable)(not affected)

Notes

- mojarra <not-affected> (DefaultFaceletFactory added in 2.3)
https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/544
https://gitlab.eclipse.org/security/cve-assignment/-/work_items/160

Search for package or bug name: Reporting problems