Back Reddit PSA: If you use pac4j for JWT authentication, you need to patch immediately, CVSS 10.0 auth bypass
Heads up for anyone running pac4j-jwt in production. CVE-2026-29000 dropped yesterday. CVSS 10.0. The issue is in JwtAuthenticator, if your app…
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
