Skip to content

OmniFaces: Forged combined-resource IDs and related output/push boundaries

High severity GitHub Reviewed Published Jul 23, 2026 in omnifaces/omnifaces • Updated Jul 24, 2026

Package

maven org.omnifaces:omnifaces (Maven)

Affected versions

< 1.14.3
>= 2.0.0, < 2.7.33
>= 3.0.0, < 3.14.23
>= 4.0.0, < 4.7.12
>= 5.0.0, < 5.4.2

Patched versions

1.14.3
2.7.33
3.14.23
4.7.12
5.4.2

Description

1. Forged combined-resource IDs

CombinedResourceInfo accepts a path-derived ID without an authenticity check,
inflates it without an output limit, converts it to attacker-selected resource
identifiers, and retains unique IDs in an unbounded static cache. In bounded
tests, 20,754 encoded bytes inflated to 16,000,000 characters (about 770:1;
about 49 MB observed heap delta), and 200 unique IDs added 200 permanent cache
entries. A legitimately shaped short ID remained about 1:1, while malformed
input was rejected; the missing distinction is between a server-issued ID and
an attacker-minted but structurally valid ID.

The minimal application also confirmed three sink tails from the same forged-ID
root:

  • A wildcard CDN mapping performed a server-side fetch and relayed the exact
    loopback-canary body. This requires the documented combined-resource and
    wildcard-CDN configuration.
  • A forged inner .xhtml resource bypassed the excluded-resource boundary and
    returned its raw content.
  • A forged omnifaces.graphic inner resource plus a canary Host header caused
    an outbound GET to that host. This result is blind and deployment-dependent;
    I am not claiming arbitrary-scheme or arbitrary-destination SSRF.

These behaviors reproduce after the fix for CVE-2026-41883 /
GHSA-vp6r-9m58-5xv8. That advisory concerned EL evaluation order in the wildcard
CDN path. This report has a different root: unsigned combined IDs and missing
decode/cache bounds, with separately demonstrated residual sink behavior.

2. Source-map cache

With the documented optional source-map handler above a synthetic resource
handler, 40 unique missing combined-resource requests grew the process-wide
source-map cache from 13 to 92 entries. It has no size or eviction bound. This
has a separate cache, configuration prerequisite, and fix from family 1.

3. HashParam callback output

A URL-fragment value containing a single-quote JavaScript payload was stored by
o:hashParam and later written unescaped into the Ajax callback script. On the
follow-up Ajax render, real Chrome executed the canary
window.__omniXss=1337. This requires a page using o:hashParam and the
follow-up Ajax render.

4. Session/view push-channel replay

A fresh WebSocket client with no HTTP cookie connected using a victim's
session-scoped channel ID and received the victim's subsequent push. The code
checks application-wide ID existence but does not bind the handshake to the
current HTTP session, despite the documented current-session guarantee. The
UUID remains an unguessable bearer-token prerequisite; this is replay after
token exposure, not brute force.

5. Push idle-connection and fanout behavior

Twelve independent clients joined one application-scoped channel and all 12
received the same push. Current code sets every accepted session's maximum idle
timeout to zero, retains sessions in an unbounded per-channel queue, and walks
the full queue on each push. I am reporting the demonstrated mechanism as a
bounded design weakness: container connection limits remain an outer bound,
and I am not claiming unbounded heap growth from the 12-client test.

Intentionally excluded leads

  • A duplicate-Range response-amplification lead was disproved. Twenty-four
    ranges produced only one response body because the stream wrapper closes
    after the first range. I am not reporting it as a security issue.
  • The older Servlets.facesRedirect XML issue is fixed on the current branch.
    I am not reporting it as a new current-upstream issue.

Expected invariants

  • Only server-issued combined IDs should be accepted; decoding and caches
    should be bounded; excluded resources and dynamic handlers should not become
    attacker-selected inner resources.
  • Dynamic URLs should not derive an outbound destination from an untrusted
    Host header.
  • Source-map lookups should not create unbounded process-lifetime state.
  • HashParam values must be escaped for a JavaScript string inside an XML
    CDATA callback.
  • Session/view push subscriptions should be bound to the owning HTTP session or
    authenticated principal; idle limits and per-channel caps should remain
    operator-controllable.

Suggested fixes and available evidence

  • Authenticate generated combined IDs with a per-deployment secret, cap
    inflated output, bound the combined cache, and avoid caching failed loads.
  • Require an existing/registered inner resource before wildcard remapping and
    reject excluded resource types at serve time.
  • Derive dynamic-resource origins from trusted configuration rather than the
    request Host value.
  • Bound or evict the source-map cache.
  • Apply JavaScript-string plus CDATA-safe encoding to HashParam callback
    values.
  • Capture and verify HTTP-session or principal ownership during the WebSocket
    handshake; retain a finite idle timeout and configurable per-channel limits.

Daniel Birtwhistle

References

@BalusC BalusC published to omnifaces/omnifaces Jul 23, 2026
Published to the GitHub Advisory Database Jul 24, 2026
Reviewed Jul 24, 2026
Last updated Jul 24, 2026

Severity

High

CVSS overall score

This score calculates overall vulnerability severity from 0 to 10 and is based on the Common Vulnerability Scoring System (CVSS).
/ 10

CVSS v3 base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High

CVSS v3 base metrics

Attack vector: More severe the more the remote (logically and physically) an attacker can be in order to exploit the vulnerability.
Attack complexity: More severe for the least complex attacks.
Privileges required: More severe if no privileges are required.
User interaction: More severe when no user interaction is required.
Scope: More severe when a scope change occurs, e.g. one vulnerable component impacts resources in components beyond its security scope.
Confidentiality: More severe when loss of data confidentiality is highest, measuring the level of data access available to an unauthorized user.
Integrity: More severe when loss of data integrity is the highest, measuring the consequence of data modification possible by an unauthorized user.
Availability: More severe when the loss of impacted component availability is highest.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS score

Weaknesses

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users. Learn more on MITRE.

Insufficient Verification of Data Authenticity

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data. Learn more on MITRE.

Allocation of Resources Without Limits or Throttling

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated. Learn more on MITRE.

Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action. Learn more on MITRE.

CVE ID

No known CVE

GHSA ID

GHSA-fp43-vj7g-pg92

Source code

Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.