{"id":"CVE-2026-46581","details":"In Eclipse Mojarra versions 2.3 and following, URL handing in `DefaultFaceletFactory` does not properly sanitize and/or block remote URLs, allowing an attacker to specify a URL to a remote Facelet which will be included and processed as part of the normal request, with the privileges of the target server. This could allow access to restricted files such as `WEB-INF/web.xml` or `/etc/passwd`.","modified":"2026-08-14T04:03:52.597040656Z","published":"2026-08-05T11:09:41.817Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/46xxx/CVE-2026-46581.json","cna_assigner":"eclipse","cwe_ids":["CWE-22","CWE-641","CWE-94"]},"references":[{"type":"WEB","url":"https://gitlab.eclipse.org/security/cve-assignment/-/work_items/160"},{"type":"WEB","url":"https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/544"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/46xxx/CVE-2026-46581.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-46581"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/eclipse-ee4j/mojarra","events":[{"introduced":"0"},{"last_affected":"35dac9cebfa7534ae0bd40465bad324ffc891f9f"},{"introduced":"56933ea9a2f056c7ea5e76ad79b74b896d219544"},{"last_affected":"acd0e7e671bc7bd0aadf9e43f00d2a0dee5c1dec"}],"database_specific":{"cpe":["cpe:2.3:a:eclipse:mojarra:*:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:mojarra:5.0.0:milestone1:*:*:*:*:*:*","cpe:2.3:a:eclipse:mojarra:5.0.0:milestone2:*:*:*:*:*:*","cpe:2.3:a:eclipse:mojarra:5.0.0:milestone3:*:*:*:*:*:*"],"extracted_events":[{"introduced":"2.3.0"},{"last_affected":"4.1.13"},{"introduced":"5.0.0-milestone1"},{"last_affected":"5.0.0-milestone1"},{"introduced":"5.0.0-milestone2"},{"last_affected":"5.0.0-milestone2"},{"introduced":"5.0.0-milestone3"},{"last_affected":"5.0.0-milestone3"}],"source":["CPE_RANGE","CPE_STRING"]}}],"versions":["5.0.0-milestone1","5.0.0-milestone2","5.0.0-milestone3","4.1.13-RELEASE","5.0.0-M3","initial-contribution","2.3.3.102"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-46581.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}