Simplesamlphp
Simplesamlphp Saml2: vulnerabilities and CVEs
Simplesamlphp Saml2 has 7 published vulnerabilities, 2 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.
CVEs7
Last 12 months2
Critical1
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-49289 | High (7.5) | 0.78% | — | Aug 19, 2026 | The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. In 4.19.2 and 4.20.2, the library permits attacker-controlled XPath transforms while processing XML signatures in specially crafted SAML… |
| CVE-2026-49283 | High (8.7) | 0.47% | — | Aug 19, 2026 | The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. Prior to versions 4.19.3, 4.20.2, 5.0.6, and 6.2.1, the HTTPArtifact::receive() flow can treat an unsigned embedded SAML Response as… |
| CVE-2025-27773 | High (8.6) | 0.39% | — | Mar 11, 2025 | The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. Prior to versions 4.17.0 and 5.0.0-alpha.20, there is a signature confusion attack in the HTTPRedirect binding. An attacker with any… |
| CVE-2023-49087 | High (7.5) | 0.19% | — | Nov 30, 2023 | xml-security is a library that implements XML signatures and encryption. Validation of an XML signature requires verification that the hash value of the related XML-document matches a specific DigestValue-value, but… |
| CVE-2018-7711 | High (8.1) | 1.2% | — | Mar 5, 2018 | HTTPRedirect.php in the saml2 library in SimpleSAMLphp before 1.15.4 has an incorrect check of return values in the signature validation utilities, allowing an attacker to get invalid signatures accepted as valid by… |
| CVE-2018-6519 | High (7.5) | 1.7% | — | Feb 2, 2018 | The SAML2 library before 1.10.4, 2.x before 2.3.5, and 3.x before 3.1.1 in SimpleSAMLphp has a Regular Expression Denial of Service vulnerability for fraction-of-seconds data in a timestamp. |
| CVE-2016-9814 | Critical (9.1) | 2.4% | — | Feb 17, 2017 | The validateSignature method in the SAML2\Utils class in SimpleSAMLphp before 1.14.10 and simplesamlphp/saml2 library before 1.9.1, 1.10.x before 1.10.3, and 2.x before 2.3.3 allows remote attackers to spoof SAML… |