Security: simplesamlphp/saml2
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
Report a vulnerability-
Incomplete fix of CVE-2026-49283: unsigned embedded Response bypasses HTTP-Artifact signature verification (no embedded-Issuer binding)GHSA-r7hw-jx6r-756g published
Aug 9, 2026 by tvdijenHigh -
SimpleSAMLphp HTTP-Artifact TLS validator confusion allows cross-IdP authentication bypassGHSA-6929-8p9f-26jx published
May 29, 2026 by tvdijenHigh -
Possible DoS via XPath TransformGHSA-5cjr-mxj5-wmrx published
May 29, 2026 by tvdijenHigh -
Incorrect signature verification for HTTP-Redirect bindingGHSA-46r4-f8gj-xg56 published
Mar 11, 2025 by tvdijenHigh -
XXE in parsing SAML messagesGHSA-pxm4-r5ph-q2m2 published
Dec 1, 2024 by tvdijenHigh -
Incorrect signature verificationGHSA-62c2-r76c-55pp published
Jun 5, 2019 by jaimeperezModerate
Learn more about advisories related to simplesamlphp/saml2 in the GitHub Advisory Database