Pac4j is a security library for authentication and authorization that is embedded across applications and frameworks as a dependency, making its vulnerabilities relevant to downstream consumers despite a narrow product footprint. The library's durable weakness profile centers on cross-site request forgery, LDAP injection, cryptographic signature verification, and pseudo-random number generation, reflecting the authentication and session-handling complexity inherent to a multi-protocol security abstraction layer. Current vulnerability counts and severity details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pac4j over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-40459HIGH PAC4J is vulnerable to LDAP Injection in multiple methods. A low-privileged remote attacker can inject crafted LDAP syntax into ID-based search parameters, potentially resulting in | Apr 17, 2026 | 8.8 | 29 | NO | NO |
CVE-2021-44878HIGH If an OpenID Connect provider supports the "none" algorithm (i.e., tokens with no signature), pac4j v5.3.0 (and prior) does not refuse it without an explicit configuration on its s | Jan 6, 2022 | 7.5 | 25 | NO | NO |
CVE-2026-40458MEDIUM PAC4J is vulnerable to Cross-Site Request Forgery (CSRF). A malicious attacker can craft a specially designed website which, when visited by a user, will automatically submit a for | Apr 17, 2026 | 6.5 | 22 | NO | NO |
CVE-2019-10755MEDIUM The SAML identifier generated within SAML2Utils.java was found to make use of the apache commons-lang3 RandomStringUtils class which makes them predictable due to RandomStringUtils | Sep 23, 2019 | 4.9 | 20 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pac4j.
Media articles that mention a CVE ID that affects a product developed by Pac4j — matched by CVE ID, not by vendor name.