CVE-2026-40458 is a Cross-Site Request Forgery (CSRF) vulnerability in PAC4J that allows attackers to bypass CSRF token protection through hash collisions in the String.hashCode() function. An attacker can craft a malicious website that, when visited by a user, automatically submits forged requests with tokens whose hashes collide with legitimate CSRF tokens, effectively reducing token security to 32 bits. The attacker requires no prior knowledge of the victim's actual token to execute the attack. The vulnerability carries a CVSS score of 6.5 (Medium) with a network-based attack vector requiring minimal complexity and user interaction. While confidentiality is not impacted, the integrity impact is high, as attackers can perform unauthorized state-changing operations including profile updates, password changes, and account linking without victim consent. PAC4J versions 5.7.10 and 6.4.1 or later contain the fix. Exploitation of this vulnerability is not currently documented in active exploitation campaigns. The EPSS score of 0.00017 indicates extremely low probability of exploitation in the wild relative to other vulnerabilities. CVE-2026-40458 does not appear on CISA's Known Exploited Vulnerabilities catalog and remains on the inactive Hot List, suggesting limited community attention and no publicly available exploit code at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.0, < 5.7.10CPE match | cpe:2.3:a:pac4j:pac4j:*:*:*:*:*:*:*:* | ||
>= 6.0, < 6.4.1CPE match | cpe:2.3:a:pac4j:pac4j:*:*:*:*:*:*:*:* | ||
>= 5.0.0, < 5.7.10CPE matchmatch criteria | cpe:2.3:a:pac4j:pac4j:*:*:*:*:*:*:*:* | ||
> 6.0.0, < 6.4.1CPE matchmatch criteria | cpe:2.3:a:pac4j:pac4j:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.