Passport-Saml Project Passport-Saml vulnerabilities
3 known vulnerabilities affecting passport-saml_project/passport-saml.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH2
Vulnerabilities
Page 1 of 1
CVE-2025-54419CRITICAL≥ 0, ≤ 3.2.42025-07-28
CVE-2025-54419 [CRITICAL] CWE-287 Node-SAML SAML Signature Verification Vulnerability
Node-SAML SAML Signature Verification Vulnerability
Node-SAML loads the assertion from the (unsigned) original response document. This is different than the parts that are verified when checking signature.
This allows an attacker to modify authentication details within a valid SAML assertion. For example, in one attack it is possible to remove any character from the SAML assertion username.
To conduct the at
ghsaosv
CVE-2022-39299HIGHCVSS 8.1fixed in 3.2.2v4.0.02022-10-12
CVE-2022-39299 [HIGH] CWE-347 CVE-2022-39299: Passport-SAML is a SAML 2.0 authentication provider for Passport, the Node.js authentication library
Passport-SAML is a SAML 2.0 authentication provider for Passport, the Node.js authentication library. A remote attacker may be able to bypass SAML authentication on a website using passport-saml. A successful attack requires that the attacker is in possession of an arbitrary IDP signed XML element. Depending on the IDP used, fully unauthenticated atta
ghsanvdosv
CVE-2021-39171HIGHCVSS 7.5fixed in 3.1.02021-08-27
CVE-2021-39171 [HIGH] CWE-400 CVE-2021-39171: Passport-SAML is a SAML 2.0 authentication provider for Passport, the Node.js authentication library
Passport-SAML is a SAML 2.0 authentication provider for Passport, the Node.js authentication library. Prior to version 3.1.0, a malicious SAML payload can require transforms that consume significant system resources to process, thereby resulting in reduced or denied service. This would be an effective way to perform a denial-of-service attack. This ha
ghsanvdosv