PatchSiren cyber security CVE debrief
CVE-2016-9955 Debian CVE debrief
CVE-2016-9955 affects SimpleSAMLphp before 1.14.11. The issue is in the SimpleSAML_XML_Validator class constructor and stems from improper conversion of return values to boolean. According to the official descriptions, that flaw may let a remote attacker spoof signatures on SAML 1 responses or cause denial of service through memory consumption. NVD rates the issue MEDIUM with a CVSS v3.0 score of 6.3.
- Vendor
- Debian
- Product
- Unknown
- CVSS
- MEDIUM 6.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-17
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-02-17
- Advisory updated
- 2026-05-13
Who should care
Administrators and operators running SimpleSAMLphp, especially environments that still process SAML 1 responses or rely on XML signature validation for authentication flows. Security teams responsible for identity, federation, and SSO infrastructure should prioritize review and patching.
Technical summary
The vulnerable behavior is described as an improper boolean conversion in the SimpleSAML_XML_Validator constructor in SimpleSAMLphp versions before 1.14.11. NVD says this can affect signature validation for SAML 1 responses, creating integrity risk if signatures can be spoofed, and may also lead to denial of service via memory consumption. The recorded weakness is CWE-20 (Improper Input Validation).
Defensive priority
Medium. The issue is publicly disclosed and can affect authentication integrity, but NVD assigns a medium CVSS score and the description does not indicate active exploitation in the supplied corpus.
Recommended defensive actions
- Upgrade SimpleSAMLphp to version 1.14.11 or later, as identified in the NVD description and vendor advisory.
- Inventory all deployments of SimpleSAMLphp, including packaged distributions, to confirm whether any instance is below 1.14.11.
- Review whether any environment still depends on SAML 1 response handling and prioritize those systems for remediation.
- Validate that XML signature checking and memory usage behave normally after patching, especially in authentication paths.
- Track vendor and distribution guidance, including the SimpleSAMLphp security notice and Debian LTS advisory, for package-specific remediation steps.
Evidence notes
CVE published on 2017-02-17 per the supplied NVD record and modified on 2026-05-13. The official NVD description states that SimpleSAMLphp before 1.14.11 may allow signature spoofing on SAML 1 responses or denial of service via memory consumption because of improper conversion of return values to boolean in SimpleSAML_XML_Validator. The supplied references include the SimpleSAMLphp security advisory and Debian LTS announcement.
Sources and references
Verified primary and authoritative sources
-
CVE-2016-9955 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2016-9955
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2016-9955 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2016-9955
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://lists.debian.org/debian-lts-announce/2018/03/msg00001.html
[email protected] - Third Party Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://simplesamlphp.org/security/201612-02
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.