Cyber News / Article / Vulnerabilities in PAC4J software

Vulnerabilities in PAC4J software
CERT Polska has received a report about vulnerabilities in PAC4J software and participated in coordination of their disclosure.
The vulnerabilityCVE-2026-40458: PAC4J is vulnerable to Cross-Site Request Forgery (CSRF). A malicious attacker can craft a specially designed website which, when visited by a user, will automatically submit a forged cross-site request with a token whose hash collides with the victim's legitimate CSRF token. Importantly, the attacker does not need to know the victimâs CSRF token or its hash prior to the attack. Collisions in the deterministic String.hashCode() function can be computed directly, reducing the effective token's security space to 32 bits. This bypasses CSRF protection, allowing profile updates, password changes, account linking, and any other state-changing operations to be performed without the victim's consent.
This issue was fixed in PAC4J versions 5.7.10 and 6.4.1
The vulnerabilityCVE-2026-40459: PAC4J is vulnerable to LDAP Injection in multiple methods. A low-privileged remote attacker can inject crafted LDAP syntax into ID-based search parameters, potentially resulting in unauthorized LDAP queries and arbitrary directory operations.
This issue was fixed in PAC4J versions 4.5.10, 5.7.10 and 6.4.1
We thank BartÅomiej Dmitruk (striga.ai) for the responsible vulnerability report.
Related articles
Android’s September 2026 Updates Patch 180 Vulnerabilities
2 days ago
Fortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome Extension
2 days ago
September 2026 Patch Tuesday: Two Exploited Zero-Days and 113 Critical Vulnerabilities Among 972 CVEs
3 days ago
