
CVE-2026-46581 In Eclipse Mojarra versions 2.3 and following, URL handing in `DefaultFaceletFactory` does not properly sanitize and/or block remote URLs, allowing an attacker to spe… https://www.cve.org/CVERecord?id=CVE-2026-46581
Post summary
A short disclosure noting that Eclipse Mojarra 2.3+ mishandles remote URLs in DefaultFaceletFactory, enabling potential attacker exploitation.

