Skip to content

Update pac4j.version [SECURITY] (major)#276

Open
renovate[bot] wants to merge 1 commit intomasterfrom
renovate/major-pac4j.version
Open

Update pac4j.version [SECURITY] (major)#276
renovate[bot] wants to merge 1 commit intomasterfrom
renovate/major-pac4j.version

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Mar 6, 2026

This PR contains the following updates:

Package Change Age Confidence
org.pac4j:pac4j-jwt 3.9.04.5.9 age confidence
org.pac4j:pac4j-http 3.9.06.3.3 age confidence

GitHub Vulnerability Alerts

CVE-2026-29000

pac4j-jwt versions prior to 4.5.9, 5.7.9, and 6.3.3 contain an authentication bypass vulnerability in JwtAuthenticator when processing encrypted JWTs that allows remote attackers to forge authentication tokens. Attackers who possess the server's RSA public key can create a JWE-wrapped PlainJWT with arbitrary subject and role claims, bypassing signature verification to authenticate as any user including administrators.


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot added automated dependencies Pull requests that update a dependency file maintenance renovate security labels Mar 6, 2026
@renovate renovate bot force-pushed the renovate/major-pac4j.version branch 2 times, most recently from 89abd16 to c2dd3b9 Compare March 12, 2026 18:18
@renovate renovate bot force-pushed the renovate/major-pac4j.version branch from c2dd3b9 to 76ad74d Compare March 18, 2026 20:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

automated dependencies Pull requests that update a dependency file maintenance renovate security

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants