CVE-2026-49289
published 2026-07-02CVE-2026-49289: SimpleSAMLphp has Possible DoS via XPath Transform ## Summary This library turned out to be vulnerable to Denial-of-Service attacks using XPath transforms. A…
high
SimpleSAMLphp has Possible DoS via XPath Transform ## Summary This library turned out to be vulnerable to Denial-of-Service attacks using XPath transforms. A mitigation has been put in place to restrict the number of transforms and to restrict transforms to only the transform-algorithms mentioned in the SAML 2.0 Core Specifications (and specifically refuse XPath transforms). ## Impact An attacker is able to send specially crafted messages to any entity relying on SimpleSAMLphp (or directly on this SAML2-library) to be able to perform a Denial-of-Service attack.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| simplesamlphp | saml2 | >= 0 < 4.20.3 | 4.20.3 |
| simplesamlphp | saml2-legacy | >= 0 < 4.20.3 | 4.20.3 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-02
Published