CVE-2026-40458

Source
https://cve.org/CVERecord?id=CVE-2026-40458
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-40458.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-40458
Aliases
Downstream
Related
Published
2026-04-17T13:18:26.308Z
Modified
2026-08-12T03:51:13.908043333Z
Severity
  • 7.0 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N CVSS Calculator
Summary
Cross-Site Request Forgery in PAC4J
Details

PAC4J is vulnerable to Cross-Site Request Forgery (CSRF). A malicious attacker can craft a specially designed website which, when visited by a user, will automatically submit a forged cross-site request with a token whose hash collides with the victim's legitimate CSRF token. Importantly, the attacker does not need to know the victim’s CSRF token or its hash prior to the attack. Collisions in the deterministic String.hashCode() function can be computed directly, reducing the effective token's security space to 32 bits. This bypasses CSRF protection, allowing profile updates, password changes, account linking, and any other state-changing operations to be performed without the victim's consent.

This issue was fixed in PAC4J versions 5.7.10 and 6.4.1

Database specific
{
    "cwe_ids": [
        "CWE-352"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/40xxx/CVE-2026-40458.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "5.0"
                },
                {
                    "fixed": "5.7.10"
                },
                {
                    "introduced": "6.0"
                },
                {
                    "fixed": "6.4.1"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ],
    "cna_assigner": "CERT-PL"
}
References

Affected packages

Git / github.com/pac4j/pac4j

Affected ranges

Type
GIT
Repo
https://github.com/pac4j/pac4j
Events
Introduced
Fixed
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "cpe": "cpe:2.3:a:pac4j:pac4j:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "5.0.0"
        },
        {
            "fixed": "5.7.10"
        },
        {
            "introduced": "0"
        },
        {
            "fixed": "6.4.1"
        }
    ],
    "source": "CPE_RANGE"
}

Affected versions

6.*
6.0.4.1
pac4j-5.*
pac4j-5.0.0
pac4j-5.0.1
pac4j-5.1.0
pac4j-5.1.1
pac4j-5.1.2
pac4j-5.1.3
pac4j-5.1.4
pac4j-5.1.5
pac4j-parent-5.*
pac4j-parent-5.2.0
pac4j-parent-5.2.1
pac4j-parent-5.3.0
pac4j-parent-5.3.1
pac4j-parent-5.4.0
pac4j-parent-5.4.2
pac4j-parent-5.4.3
pac4j-parent-5.4.4
pac4j-parent-5.4.5
pac4j-parent-5.4.6
pac4j-parent-5.5.0
pac4j-parent-5.6.0
pac4j-parent-5.6.1
pac4j-parent-5.7.0
pac4j-parent-5.7.1
pac4j-parent-5.7.2
pac4j-parent-5.7.3
pac4j-parent-5.7.4
pac4j-parent-5.7.5
pac4j-parent-5.7.6
pac4j-parent-5.7.7
pac4j-parent-5.7.8
pac4j-parent-5.7.9
pac4j-parent-6.*
pac4j-parent-6.0.0
pac4j-parent-6.0.0-RC1
pac4j-parent-6.0.0-RC10
pac4j-parent-6.0.0-RC2
pac4j-parent-6.0.0-RC3
pac4j-parent-6.0.0-RC4
pac4j-parent-6.0.0-RC5
pac4j-parent-6.0.0-RC6
pac4j-parent-6.0.0-RC7
pac4j-parent-6.0.0-RC8
pac4j-parent-6.0.0-RC9
pac4j-parent-6.0.1
pac4j-parent-6.0.2
pac4j-parent-6.0.3
pac4j-parent-6.0.4
pac4j-parent-6.0.5
pac4j-parent-6.0.6
pac4j-parent-6.1.0
pac4j-parent-6.1.1
pac4j-parent-6.1.2
pac4j-parent-6.1.3
pac4j-parent-6.2.0
pac4j-parent-6.2.1
pac4j-parent-6.2.2
pac4j-parent-6.3.0
pac4j-parent-6.3.1
pac4j-parent-6.3.2
pac4j-parent-6.4.0
pac4j-parent-6.4.0-RC1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-40458.json"