How to use this reference
Treat authenticity checks as mandatory, fail-closed prerequisites for profile creation. Review all accepted token representations. The maintainer confirms remediation and directs upgrades to 4.5.9, 5.7.9 or 6.3.3 and newer within those release lines.
Before reading
- Basic authentication and access-control concepts
- Familiarity with application trust boundaries
Context and limits
- The demonstrated configuration uses RSA-encrypted JWTs with signature and encryption configuration; exposure cannot be inferred from any pac4j dependency alone.
- Application-specific consequences depend on how authenticated claims map to authorization.
- The maintainer confirms the issue and research credit but withholds technical details; the detailed mechanism remains researcher evidence.
- Article publication is separate from reporting and patch events. The article describes February 28 private disclosure and patches by March 2, 2026; exact version-release dates are not recorded here.
Sources and provenance
- CVE-2026-29000: pac4j-jwt Auth Bypass PoC With a Public Key CodeAnt AI · reviewed 2026-10-03
- Security advisory for pac4j-jwt (JwtAuthenticator) pac4j · reviewed 2026-10-03
Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.