CVE-2026-82464
pac4j-core before 6.5.6 contains an open redirect vulnerability in DefaultLogoutLogic.perform() that accepts backslash-prefixed logout redirect targets matching logoutUrlPattern. Attackers can craft logout links with backslash-prefixed external hosts that browsers normalize into network-path references, redirecting victims to attacker-controlled sites after logout.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.1
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
- EPSS probability
- 0.20%
- CWE
- CWE-601
- Published
- 2026-08-29
- Last modified
- 2026-09-01
Affected products
- pac4j pac4j
Weakness type
Related vulnerabilities
- CVE-2026-88887 — Renovate before 44.11.2 Credential Exfiltration via Link Header
- CVE-2026-88882 — Renovate before 44.11.2 Credential Exfiltration via Link Header
- CVE-2026-88881 — Renovate before 44.11.3 Credential Exfiltration via Link Header
- CVE-2026-88880 — Renovate before 44.11.3 Credential Exfiltration via Link Header
- CVE-2026-8323 — Open Redirect in Armiya Information Technologies' Access Control System
- CVE-2026-86756 — Snipe-IT 8.5.0 through 8.6.3 Open Redirect via SAML RelayState
- CVE-2026-78377 — Open Redirect in Yordam Informatics's Library Automation System
- CVE-2026-84389 — A url redirection to untrusted site ('open redirect') vulnerability in Fortinet FortiSIEM 7.5.0...