PT-2025-13818 · Jooby+1 · Jooby+1

Published

2025-03-31

·

Updated

2025-04-01

·

CVE-2025-31129

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Jooby versions prior to 2.17.0 Jooby versions prior to 3.7.0
Description The issue concerns the deserialization of untrusted data by the SessionStoreImpl#get module in the pac4j library of the Jooby web framework for Java and Kotlin.
Recommendations For versions prior to 2.17.0, update to version 2.17.0 or later. For versions prior to 3.7.0, update to version 3.7.0 or later.

Exploit

Fix

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2025-31129
GHSA-7C5V-895V-W4Q5

Affected Products

Jooby
Pac4J