Back to Database
Status published
High
CVE-2025-31129
jooby-pac4j: deserialization of untrusted data
Vulnerability Description
Jooby is a web framework for Java and Kotlin. The pac4j io.jooby.internal.pac4j.SessionStoreImpl#get module deserializes untrusted data. This vulnerability is fixed in 2.17.0 (2.x) and 3.7.0 (3.x).
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-31129
Credits & Attribution
No credits recorded in the NVD database.
References
- https://github.com/jooby-project/jooby/security/advisories/GHSA-7c5v-895v-w4q5
- https://github.com/jooby-project/jooby/commit/3e13562cf36d7407813eae464e0f4b598de15692
- https://github.com/jooby-project/jooby/blob/v2.x/modules/jooby-pac4j/src/main/java/io/jooby/internal/pac4j/SessionStoreImpl.java#L39-L45
- https://github.com/jooby-project/jooby/blob/v3.6.1/modules/jooby-pac4j/src/main/java/io/jooby/internal/pac4j/SessionStoreImpl.java#L77-L84
Affected Vendor
jooby-project
View all reports →Affected Software
jooby
Vulnerable Versions:
>= 3.0.0.M1, < 3.7.0, < 2.17.0
Timeline
Official Publish:
March 31st, 2025
Last Modified:
April 1st, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H