Skip to main content

Vendor/product archive

pac4j / pac4j CVEs

Beta · best-effort

4 CVEs tagged to pac4j / pac4j0 Critical, 3 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2026-40459

Published Apr 17, 2026

PAC4J is vulnerable to LDAP Injection in multiple methods. A low-privileged remote attacker can inject crafted LDAP syntax into ID-based search parameters, potentially resulting i…

CVSS 8.7 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-40458

Published Apr 17, 2026

PAC4J is vulnerable to Cross-Site Request Forgery (CSRF). A malicious attacker can craft a specially designed website which, when visited by a user, will automatically submit a fo…

CVSS 7.0 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2021-44878

Published Jan 6, 2022

If an OpenID Connect provider supports the "none" algorithm (i.e., tokens with no signature), pac4j v5.3.0 (and prior) does not refuse it without an explicit configuration on its…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-10755

Published Sep 23, 2019

The SAML identifier generated within SAML2Utils.java was found to make use of the apache commons-lang3 RandomStringUtils class which makes them predictable due to RandomStringUtil…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1