CVE-2026-82464

pac4j-core before 6.5.6 contains an open redirect vulnerability in DefaultLogoutLogic.perform() that accepts backslash-prefixed logout redirect targets matching logoutUrlPattern. Attackers can craft logout links with backslash-prefixed external hosts that browsers normalize into network-path references, redirecting victims to attacker-controlled sites after logout.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-29 17:17

Updated : 2026-09-10 19:54


NVD link : CVE-2026-82464

Mitre link : CVE-2026-82464

CVE.ORG link : CVE-2026-82464


JSON object : View

Products Affected

No product.

CWE
CWE-601

URL Redirection to Untrusted Site ('Open Redirect')