See how pam tacplus project compares to other vendors in security performance
In pamtacplus.c in pamtacplus before 1.4.1, pamsmacctmgmt does not zero out the arep data structure.
libtac in pamtacplus through 1.5.1 lacks a check for a failure of RANDbytes()/RANDpseudobytes(). This could lead to use of a non-random/predictable sessionid.
In support.c in pamtacplus 1.3.8 through 1.5.1, the TACACS+ shared secret gets logged via syslog if the DEBUG loglevel and journald are used.