HIGH8.6Packagist
GHSA-46r4-f8gj-xg56· CVE-2025-27773The SimpleSAMLphp SAML2 library incorrectly verifies signatures for HTTP-Redirect binding
Modified: 9/10/2026
package
pkg:packagist/simplesamlphp/saml2-legacy
The SimpleSAMLphp SAML2 library incorrectly verifies signatures for HTTP-Redirect binding
Modified: 9/10/2026
SimpleSAMLphp has Possible DoS via XPath Transform
Modified: 8/5/2026
SimpleSAMLphp HTTP-Artifact TLS validator confusion allows cross-IdP authentication bypass
Modified: 8/4/2026
SimpleSAMLphp SAML2 has an XXE in parsing SAML messages
Modified: 12/13/2024