cbcvebase.
CVE-2026-49289
published 2026-07-02

CVE-2026-49289: SimpleSAMLphp has Possible DoS via XPath Transform ## Summary This library turned out to be vulnerable to Denial-of-Service attacks using XPath transforms. A…

high
SimpleSAMLphp has Possible DoS via XPath Transform

## Summary

This library turned out to be vulnerable to Denial-of-Service attacks using XPath transforms. A mitigation has been put in place to restrict the number of transforms and to restrict transforms to only the transform-algorithms mentioned in the SAML 2.0 Core Specifications (and specifically refuse XPath transforms).

## Impact

An attacker is able to send specially crafted messages to any entity relying on SimpleSAMLphp (or directly on this SAML2-library) to be able to perform a Denial-of-Service attack.

Affected

2 ranges
VendorProductVersion rangeFixed in
simplesamlphpsaml2>= 0 < 4.20.34.20.3
simplesamlphpsaml2-legacy>= 0 < 4.20.34.20.3
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.