« Back to list

Simplesamlphp

Simplesamlphp Saml2: vulnerabilities and CVEs

Simplesamlphp Saml2 has 7 published vulnerabilities, 2 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.

CVEs7
Last 12 months2
Critical1
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-49289High (7.5)0.78%—Aug 19, 2026
The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. In 4.19.2 and 4.20.2, the library permits attacker-controlled XPath transforms while processing XML signatures in specially crafted SAML…
CVE-2026-49283High (8.7)0.47%—Aug 19, 2026
The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. Prior to versions 4.19.3, 4.20.2, 5.0.6, and 6.2.1, the HTTPArtifact::receive() flow can treat an unsigned embedded SAML Response as…
CVE-2025-27773High (8.6)0.39%—Mar 11, 2025
The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. Prior to versions 4.17.0 and 5.0.0-alpha.20, there is a signature confusion attack in the HTTPRedirect binding. An attacker with any…
CVE-2023-49087High (7.5)0.19%—Nov 30, 2023
xml-security is a library that implements XML signatures and encryption. Validation of an XML signature requires verification that the hash value of the related XML-document matches a specific DigestValue-value, but…
CVE-2018-7711High (8.1)1.2%—Mar 5, 2018
HTTPRedirect.php in the saml2 library in SimpleSAMLphp before 1.15.4 has an incorrect check of return values in the signature validation utilities, allowing an attacker to get invalid signatures accepted as valid by…
CVE-2018-6519High (7.5)1.7%—Feb 2, 2018
The SAML2 library before 1.10.4, 2.x before 2.3.5, and 3.x before 3.1.1 in SimpleSAMLphp has a Regular Expression Denial of Service vulnerability for fraction-of-seconds data in a timestamp.
CVE-2016-9814Critical (9.1)2.4%—Feb 17, 2017
The validateSignature method in the SAML2\Utils class in SimpleSAMLphp before 1.14.10 and simplesamlphp/saml2 library before 1.9.1, 1.10.x before 1.10.3, and 2.x before 2.3.3 allows remote attackers to spoof SAML…

Other products by Simplesamlphp