OmniFaces is a utility library for Faces. Prior to versions 1.14.2, 2.7.32, 3.14.16, 4.7.5, and 5.2.3, there is a server-side EL injection leading to Remote Code Execution (RCE). This affects applications that use CDNResourceHandler with a wildcard CDN mapping (e.g. libraryName:=https://cdn.example.com/). An attacker can craft a resource request URL containing an EL expression in the resource name, which is evaluated server-side. This issue has been patched in versions 1.14.2, 2.7.32, 3.14.16, 4.7.5, and 5.2.3.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-917"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/41xxx/CVE-2026-41883.json"
}{
"source": "AFFECTED_FIELD",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "1.14.2"
},
{
"introduced": "2.0-RC1"
},
{
"fixed": "2.7.32"
},
{
"introduced": "3.0-RC1"
},
{
"fixed": "3.14.16"
},
{
"introduced": "5.0-M1"
},
{
"fixed": "5.2.3"
},
{
"introduced": "4.0-M1"
},
{
"fixed": "4.7.5"
}
]
}