A newly disclosed critical vulnerability in the widely used pac4j authentication framework is drawing attention across the open source community. Tracked as CVE-2026-29000, the flaw affects the pac4j-jwt library, which is commonly pulled in as a dependency by many popular Java authentication stacks, and could allow attackers to bypass authentication controls in affected Java applications.
The post pac4j CVE-2026-29000: Sonatype Finds 18 Additional Packages appeared first on Security Boulevard.
Sonatype Security Research Team
Source: Security Boulevard
Source Link: https://securityboulevard.com/2026/03/pac4j-cve-2026-29000-sonatype-finds-18-additional-packages/