pac4j
5 known vulnerabilities in pac4j, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-82465 CVSS 6.9 medium pac4j-saml before 6.5.6 does not require signature validation of SAML LogoutRequest messages in…
- CVE-2026-82464 CVSS 5.3 medium pac4j-core before 6.5.6 contains an open redirect vulnerability in DefaultLogoutLogic.perform() that accepts backslash-prefixed logout…
- CVE-2026-82463 CVSS 8.6 high pac4j-core before 6.5.6 contains an authentication bypass vulnerability in CheckProfileTypeAuthorizer that reverses the profile type…
- CVE-2026-82462 CVSS 6.9 medium pac4j-oidc before 6.5.6 accepts OIDC callbacks carrying only an access token without authorization code or ID token validation. Attackers…
- CVE-2026-82461 CVSS 8.6 high pac4j-oidc before 6.5.6 fails to verify access token signatures, issuers, audiences, or expiry when extracting Keycloak realm and client…