pac4j CVE-2026-29000: Sonatype Finds 18 Additional Packages

A newly disclosed critical vulnerability in the widely used pac4j authentication framework is drawing attention across the open source community. Tracked as CVE-2026-29000, the flaw affects the pac4j-jwt library, which is commonly pulled in as a dependency by many popular Java authentication stacks, and could allow attackers to bypass authentication controls in affected Java applications.

The post pac4j CVE-2026-29000: Sonatype Finds 18 Additional Packages appeared first on Security Boulevard.

This article has been indexed from Security Boulevard

Read the original article: