cbcvebase.

Simplesamlphp Saml2 vulnerabilities

9 known vulnerabilities affecting simplesamlphp/saml2.

Total CVEs
9
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH8

Vulnerabilities

Page 1 of 1
CVE-2025-27773P3HIGHCVSS 8.6fixed in 4.17.0v>= 5.0.0-alpha.1, < 5.0.0-alpha.202025-03-11
CVE-2025-27773 [HIGH] CWE-347 CVE-2025-27773: The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. Prior to versions The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. Prior to versions 4.17.0 and 5.0.0-alpha.20, there is a signature confusion attack in the HTTPRedirect binding. An attacker with any signed SAMLResponse via the HTTP-Redirect binding can cause the application to accept an unsigned message. Versions 4.17.0 and 5.0.0-alpha.
ghsanvdosv
CVE-2024-52806P3HIGHCVSS 8.3fixed in 4.6.14v>= 5.0.0-alpha.1, < 5.0.0-alpha.182024-12-02
CVE-2024-52806 [HIGH] CWE-611 CVE-2024-52806: SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. When loading an (untru SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. When loading an (untrusted) XML document, for example the SAMLResponse, it's possible to induce an XXE. This vulnerability is fixed in 4.6.14 and 5.0.0-alpha.18.
ghsanvdosv
CVE-2016-9814P3CRITICALCVSS 9.1≤ 1.9v1.10+9 more2017-02-17
CVE-2016-9814 [CRITICAL] CWE-399 CVE-2016-9814: The validateSignature method in the SAML2\Utils class in SimpleSAMLphp before 1.14.10 and simplesaml The validateSignature method in the SAML2\Utils class in SimpleSAMLphp before 1.14.10 and simplesamlphp/saml2 library before 1.9.1, 1.10.x before 1.10.3, and 2.x before 2.3.3 allows remote attackers to spoof SAML responses or possibly cause a denial of service (memory consumption) by leveraging improper conversion of return values to boolean.
ghsanvdosv
CVE-2018-7711P3HIGHCVSS 8.1≥ 1.0.0, < 1.10.6≥ 2.0.0, < 2.3.8+1 more2018-03-05
CVE-2018-7711 [HIGH] CWE-347 CVE-2018-7711: HTTPRedirect.php in the saml2 library in SimpleSAMLphp before 1.15.4 has an incorrect check of retur HTTPRedirect.php in the saml2 library in SimpleSAMLphp before 1.15.4 has an incorrect check of return values in the signature validation utilities, allowing an attacker to get invalid signatures accepted as valid by forcing an error during validation. This occurs because of a dependency on PHP functionality that interprets a -1 error code as a true bool
ghsanvdosv
CVE-2023-49087P3HIGHCVSS 7.5v5.0.02023-11-30
CVE-2023-49087 [HIGH] CWE-345 CVE-2023-49087: xml-security is a library that implements XML signatures and encryption. Validation of an XML signat xml-security is a library that implements XML signatures and encryption. Validation of an XML signature requires verification that the hash value of the related XML-document matches a specific DigestValue-value, but also that the cryptographic signature on the SignedInfo-tree (the one that contains the DigestValue) verifies and matches a trusted publi
ghsanvdosv
CVE-2018-7644P3HIGH≥ 0, < 1.10.5≥ 2.0, < 2.3.7+1 more2022-05-13
CVE-2018-7644 [HIGH] CWE-347 SimpleSAMLphp Improper Verification of Cryptographic Signature SimpleSAMLphp Improper Verification of Cryptographic Signature The XmlSecLibs library as used in the saml2 library in SimpleSAMLphp before 1.15.3 incorrectly verifies signatures on SAML assertions, allowing a remote attacker to construct a crafted SAML assertion on behalf of an Identity Provider that would pass as cryptographically valid, thereby allowing them to impersonate a user from that Identity Pro
ghsaosv
CVE-2018-6519P4HIGHCVSS 7.5≥ 1.0.0, < 1.10.4≥ 2.0.0, < 2.3.5+1 more2018-02-02
CVE-2018-6519 [HIGH] CWE-74 CVE-2018-6519: The SAML2 library before 1.10.4, 2.x before 2.3.5, and 3.x before 3.1.1 in SimpleSAMLphp has a Regul The SAML2 library before 1.10.4, 2.x before 2.3.5, and 3.x before 3.1.1 in SimpleSAMLphp has a Regular Expression Denial of Service vulnerability for fraction-of-seconds data in a timestamp.
ghsanvdosv
CVE-2026-49283HIGH≥ 6.0.0, < 6.2.1≥ 5.0.0, < 5.0.6+1 more2026-07-02
CVE-2026-49283 [HIGH] CWE-295 SimpleSAMLphp HTTP-Artifact TLS validator confusion allows cross-IdP authentication bypass SimpleSAMLphp HTTP-Artifact TLS validator confusion allows cross-IdP authentication bypass ## Summary SimpleSAMLphp's HTTP-Artifact receive path can treat an unsigned embedded SAML `Response` as cryptographically valid for the wrong IdP. In the `HTTPArtifact::receive()` flow, the SOAP `ArtifactResponse` receives a TLS-based validator from `SOAPClient::addSSLValidator()`. Th
ghsa
CVE-2026-49289HIGH≥ 0, < 4.20.32026-07-02
CVE-2026-49289 [HIGH] CWE-400 SimpleSAMLphp has Possible DoS via XPath Transform SimpleSAMLphp has Possible DoS via XPath Transform ## Summary This library turned out to be vulnerable to Denial-of-Service attacks using XPath transforms. A mitigation has been put in place to restrict the number of transforms and to restrict transforms to only the transform-algorithms mentioned in the SAML 2.0 Core Specifications (and specifically refuse XPath transforms). ## Impact An attacker is able to send
ghsa
Simplesamlphp Saml2 vulnerabilities | cvebase