highCVSS 7.5Vulnerability

GHSA-fp43-vj7g-pg92

## 1. Forged combined-resource IDs `CombinedResourceInfo` accepts a path-derived ID without an authenticity check, inflates it without an output limit, converts it to attacker-selected resource identifiers, and retains unique IDs in an unbounded static cache. In bounded tests, 20,754 encoded bytes inflated to 16,000,000 characters (about 770:1; about 49 MB observed heap delta), and 200 unique IDs added 200 permanent cache entries. A legitimately shaped short ID remained about 1:1, while malformed input was rejected; the missing distinction is between a server-issued ID and an attacker-minted but structurally valid ID. The minimal application also confirmed three sink tails from the same forged-ID root: - A wildcard CDN mapping performed a server-side fetch and relayed the exact loopback-canary body. This requires the documented combined-resource and wildcard-CDN configuration. - A forged inner `.xhtml` resource bypassed the excluded-resource boundary and returned its raw content. - A forged `omnifaces.graphic` inner resource plus a canary `Host` header caused an outbound GET to that host. This result is blind and deployment-dependent; I am not claiming arbitrary-scheme or arbitrary-destination SSRF. These behaviors reproduce after the fix for CVE-2026-41883 / GHSA-vp6r-9m58-5xv8. That advisory concerned EL evaluation order in the wildcard CDN path. This report has a different root: unsigned combined IDs and missing decode/cache bounds, with separately demonstrated residual sink behavior. ## 2. Source-map cache With the documented optional source-map handler above a synthetic resource handler, 40 unique missing combined-resource requests grew the process-wide source-map cache from 13 to 92 entries. It has no size or eviction bound. This has a separate cache, configuration prerequisite, and fix from family 1. ## 3. HashParam callback output A URL-fragment value containing a single-quote JavaScript payload was stored by `o:hashParam` and later written

Properties

ghsa_id
GHSA-fp43-vj7g-pg92
severity
high
summary
OmniFaces: Forged combined-resource IDs and related output/push boundaries
cvss_score
7.5
cve_id
GHSA-fp43-vj7g-pg92
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
is_ghsa_only
true
ghsa_published
2026-07-24T22:35:27Z
source_url
https://github.com/advisories/GHSA-fp43-vj7g-pg92
ghsa_updated
2026-07-24T22:35:29Z

Related Entities (7)

VULNERABLE_TO (1)

[Software]maven/org.omnifaces:omnifaces

AFFECTS (1)

[Software]maven/org.omnifaces:omnifaces

HAS_WEAKNESS (4)

[Weakness]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
[Weakness]Missing Authorization
[Weakness]Insufficient Verification of Data Authenticity
[Weakness]Allocation of Resources Without Limits or Throttling

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph