pac4j-core before 6.5.6 contains an open redirect vulnerability in DefaultLogoutLogic.perform() that accepts backslash-prefixed logout redirect targets matching logoutUrlPattern. Attackers can craft logout links with backslash-prefixed external hosts that browsers normalize into network-path references, redirecting victims to attacker-controlled sites after logout.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-29 17:17
Updated : 2026-09-10 19:54
NVD link : CVE-2026-82464
Mitre link : CVE-2026-82464
CVE.ORG link : CVE-2026-82464
JSON object : View
Products Affected
No product.
CWE
CWE-601
URL Redirection to Untrusted Site ('Open Redirect')
