VDB
Sign up
CRITICAL

GHSA-5j8p-438x-rgg5

SAML PHP Toolkit Vulnerability on xmlseclibs CVE-2025-66475

Quick fix

GHSA-5j8p-438x-rgg5 — onelogin/php-saml: upgrade to the fixed version with the command below.

composer require onelogin/php-saml:^2.21.1

Details

**Summary**

There is a critical vulnerability on xmlseclibs [CVE-2025-66475](https://github.com/robrichards/xmlseclibs/security/advisories/GHSA-c4cc-x928-vjw9), a dependency of php-saml

Update to the following versions of php-saml which forces the use of patched versions of xmlseclibs: - [2.21.1](https://github.com/SAML-Toolkits/php-saml/releases/tag/2.21.1) - [3.8.1](https://github.com/SAML-Toolkits/php-saml/releases/tag/3.8.1) - [4.3.1](https://github.com/SAML-Toolkits/php-saml/releases/tag/4.3.1)

**Impact**

Signature Wrapping Vulnerabilities allows an attacker to impersonate a user.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/onelogin/php-saml
Introduced in: 0Fixed in: 2.21.1
Fixcomposer require onelogin/php-saml:^2.21.1
Packagist/onelogin/php-saml
Introduced in: 3.0.0Fixed in: 3.8.1
Fixcomposer require onelogin/php-saml:^3.8.1
Packagist/onelogin/php-saml
Introduced in: 4.0.0Fixed in: 4.3.1
Fixcomposer require onelogin/php-saml:^4.3.1

References