The Null-Signature Trap: Unmasking the 10.0 CVSS Authentication Bypass in pac4j-jwt