Security advisory for pac4j-core on CSRF (again)

A security vulnerability affecting the CSRF support in the pac4j-core module has been identified and fixed.

To stay safe, you SHOULD upgrade to v6.5.9 (or newer)

No additional details will be shared in this post.

You MUST upgrade vs You SHOULD upgrade

Each security advisory tells you how urgent the upgrade is:
- You MUST upgrade: you have no choice. The vulnerability affects everyone using the module and/or it is extremely severe. Upgrade immediately.
- You SHOULD upgrade: the vulnerability is moderate and/or it can only be reproduced under rather unlikely conditions. Plan the upgrade, but there is no need to panic.
The number of security advisories has increased recently, which may sound alarming. AI-powered tools have fundamentally changed the security landscape, making it much easier and faster to identify potential vulnerabilities and weaknesses.
While this may initially seem like a bad thing, it is actually a positive development: it is far better to remain vigilant and fix security issues than to overlook them and have a false sense of security.
Security advisories are not necessarily a sign of poor code quality. They also reflect a project's visibility, widespread use, and active security scrutiny. Open-source software can be publicly inspected, tested, and continuously improved—provided that reported issues are addressed promptly.

The practical takeaway is clear: use the latest mature version of pac4j and apply security updates as soon as possible.
Jérôme LELEU - September 2026