Fork me on GitHub

Security advisory for pac4j-core and pac4j-ldap

A security vulnerability affecting the CSRF support in the pac4j-core module has been identified and fixed.

To stay safe, you SHOULD upgrade:

Another security vulnerability affecting the LdapProfileService in the pac4j-ldap module has been identified and fixed.

To stay safe, you MUST upgrade:

No additional details will be shared in this post.

These vulnerabilities were discovered by Bartlomiej Dmitruk, striga.ai.

Jérôme LELEU - April 2026