GHSA-5j8p-438x-rgg5
SAML PHP Toolkit Vulnerability on xmlseclibs CVE-2025-66475
Quick fix
GHSA-5j8p-438x-rgg5 — onelogin/php-saml: upgrade to the fixed version with the command below.
composer require onelogin/php-saml:^2.21.1Details
**Summary**
There is a critical vulnerability on xmlseclibs [CVE-2025-66475](https://github.com/robrichards/xmlseclibs/security/advisories/GHSA-c4cc-x928-vjw9), a dependency of php-saml
Update to the following versions of php-saml which forces the use of patched versions of xmlseclibs: - [2.21.1](https://github.com/SAML-Toolkits/php-saml/releases/tag/2.21.1) - [3.8.1](https://github.com/SAML-Toolkits/php-saml/releases/tag/3.8.1) - [4.3.1](https://github.com/SAML-Toolkits/php-saml/releases/tag/4.3.1)
**Impact**
Signature Wrapping Vulnerabilities allows an attacker to impersonate a user.
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 2.21.1composer require onelogin/php-saml:^2.21.13.0.0Fixed in: 3.8.1composer require onelogin/php-saml:^3.8.14.0.0Fixed in: 4.3.1composer require onelogin/php-saml:^4.3.1References
- https://github.com/SAML-Toolkits/php-saml/security/advisories/GHSA-5j8p-438x-rgg5[WEB]
- https://github.com/robrichards/xmlseclibs/security/advisories/GHSA-c4cc-x928-vjw9[WEB]
- https://github.com/SAML-Toolkits/php-saml[PACKAGE]
- https://github.com/SAML-Toolkits/php-saml/releases/tag/2.21.1[WEB]
- https://github.com/SAML-Toolkits/php-saml/releases/tag/3.8.1[WEB]
- https://github.com/SAML-Toolkits/php-saml/releases/tag/4.3.1[WEB]