
CVE-2026-40458 PAC4J is vulnerable to Cross-Site Request Forgery (CSRF). A malicious attacker can craft a specially designed website which, when visited by a user, will automaticall… https://www.cve.org/CVERecord?id=CVE-2026-40458
Post summary
The passage announces CVE‑2026‑40458 as a CSRF vulnerability in PAC4J, noting that an attacker can craft a malicious website; no PoC, exploit, patch, or active exploitation is mentioned.

