CYBERSECURITYTRACKER
TRACKING6,877 stories in this site build1,441 vulnerability news stories in this site build
Permanent story citation

CVE-2026-76646: Apache MyFaces: Denial of Service via Unbounded Request Parsing

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 7537

As cited

Copy frozen at (site build).

vulnerabilities

CVE-2026-76646: Apache MyFaces: Denial of Service via Unbounded Request Parsing

Apache MyFaces versions 2.2.0 through 4.1.3 contain a denial of service (DoS) vulnerability (CVE-2026-76646) in request parsing that allows an attacker to trigger excessive resource consumption through specially crafted request parameters. The issue is classified as critical severity across multiple affected version lines.

Why it matters: Organizations running vulnerable Apache MyFaces instances should apply patches immediately, as remote attackers can crash or degrade web application availability without authentication.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary