HIGH8.6Packagist
GHSA-46r4-f8gj-xg56· CVE-2025-27773The SimpleSAMLphp SAML2 library incorrectly verifies signatures for HTTP-Redirect binding
Modified: 9/10/2026
package
pkg:packagist/simplesamlphp/saml2
The SimpleSAMLphp SAML2 library incorrectly verifies signatures for HTTP-Redirect binding
Modified: 9/10/2026
SimpleSAMLphp has Possible DoS via XPath Transform
Modified: 8/5/2026
SimpleSAMLphp HTTP-Artifact TLS validator confusion allows cross-IdP authentication bypass
Modified: 8/4/2026
SimpleSAMLphp Improper Verification of Cryptographic Signature
Modified: 4/25/2024
SimpleSAMLphp saml2 incorrect signature validation
Modified: 2/16/2024
SimpleSAMLphp SAML2 library Regular Expression Denial of Service vulnerability
Modified: 4/25/2024
SimpleSAMLphp SAML2 has an XXE in parsing SAML messages
Modified: 12/13/2024
SimpleSAMLphp SAML2 spoof SAML responses
Modified: 12/7/2024
Validation of SignedInfo
Modified: 9/10/2026