Simplesamlphp / Saml2
8 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-49289 | SimpleSAMLphp SAML2: Possible DoS via XPath Transform | HIGH | 7.5 | Aug 19, 2026 |
| CVE-2026-49283 | SimpleSAMLphp HTTP-Artifact TLS validator confusion allows cross-IdP authentication bypass | HIGH | 8.7 | Aug 19, 2026 |
| CVE-2025-27773 | SimpleSAMLphp SAML2 library has incorrect signature verification for HTTP-Redirect binding | HIGH | 8.6 | Mar 11, 2025 |
| CVE-2024-52806 | SimpleSAMLphp SAML2 has an XXE in parsing SAML messages | MEDIUM | 6.9 | Dec 2, 2024 |
| CVE-2023-49087 | Validation of SignedInfo | HIGH | 7.5 | Nov 30, 2023 |
| CVE-2018-7711 | HTTPRedirect.php in the saml2 library in SimpleSAMLphp before 1.15.4 has an incorrect check of return values in the signature validation utilities, allowing an… | HIGH | 8.1 | Mar 5, 2018 |
| CVE-2018-6519 | The SAML2 library before 1.10.4, 2.x before 2.3.5, and 3.x before 3.1.1 in SimpleSAMLphp has a Regular Expression Denial of Service vulnerability for fraction-… | HIGH | 7.5 | Feb 2, 2018 |
| CVE-2016-9814 | The validateSignature method in the SAML2\Utils class in SimpleSAMLphp before 1.14.10 and simplesamlphp/saml2 library before 1.9.1, 1.10.x before 1.10.3, and 2… | CRITICAL | 9.1 | Feb 16, 2017 |
Showing 1 to 8 of 8 CVEs