All 8 CVE vulnerabilities found in pac4j, with AI-generated Chinese analysis, references, and POCs.
Vendor: pac4j
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-82465 | pac4j-saml before 6.5.6 Session Destruction via Unsigned LogoutRequest CWE-345 | 5.3 | Medium | 2026-08-29 |
| CVE-2026-82464 | pac4j-core before 6.5.6 Open Redirect via Backslash Logout CWE-601 | 6.1 | Medium | 2026-08-29 |
| CVE-2026-82463 | pac4j-core before 6.5.6 Authorization Bypass via Reversed Profile Type Check CWE-863 | 8.1 | High | 2026-08-29 |
| CVE-2026-82462 | pac4j-oidc before 6.5.6 Authentication Bypass via Access Token Substitution CWE-345 | 6.5 | Medium | 2026-08-29 |
| CVE-2026-82461 | pac4j-oidc before 6.5.6 Privilege Escalation via Unverified Keycloak Access Token CWE-347 | 8.1 | High | 2026-08-29 |
| CVE-2026-40459 | LDAP Injection in PAC4J CWE-90 | 8.1AI | High AI | 2026-04-17 |
| CVE-2026-40458 | Cross-Site Request Forgery in PAC4J CWE-352 | 6.5AI | Medium AI | 2026-04-17 |
| CVE-2023-25581 | Deserialization of untrusted data in InternalAttributeHandler in pac4j CWE-502 | 9.8AI | Critical AI | 2024-10-10 |
All 8 known CVE vulnerabilities affecting pac4j with full Chinese analysis, references, and POCs where available.