These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
A vulnerability in the SimpleSAMLphp SAML2 library permits attacker-controlled XPath transforms, potentially allowing a remote unauthenticated attacker to deny service to any entity relying on SimpleSAMLphp or directly on the SAML2 library. This issue affects versions 4.19.2 and 4.20.2, and is fixed in versions 4.19.3 and 4.20.3. Entities using SimpleSAMLphp or the SAML2 library should assess their exposu [truncated]
The SimpleSAMLphp SAML2 library is vulnerable to an issue where an unsigned embedded SAML Response can be treated as cryptographically valid for the wrong identity provider, allowing for authentication as arbitrary users with attacker-chosen assertion attributes, NameID, and session data in a multi-IdP federation. This issue arises from improper validation in the HTTPArtifact::receive() flow, specifically [truncated]
CVE-2026-49284 is an information disclosure vulnerability in SimpleSAMLphp versions before 1.18.6. The vulnerability occurs when the SAML SP ACS path does not enforce the IdP selected for an SP-initiated login when unsigned Response/InResponseTo is combined with a signed assertion lacking SubjectConfirmationData/InResponseTo. This issue allows a response issued by one trusted IdP to be bound to SP state c [truncated]
CVE-2025-65954 affects SimpleSAMLphp-casserver, a CAS 1.0/2.0 compliant CAS server module for SimpleSAMLphp. In affected versions below 6.3.1 and 7.0.0, the logout endpoint accepts a url query parameter and treats it as trusted. Depending on configuration, the browser is redirected to that URL or shown a logout page with a follow-on link. The issue is fixed in versions 6.3.1 and 7.0.0.
CVE-2016-9814 is a critical authentication flaw in SimpleSAMLphp and the simplesamlphp/saml2 library. The issue is in validateSignature, where improper conversion of return values to boolean can let a remote attacker spoof SAML responses and may also trigger denial of service through memory consumption.
CVE-2016-3124 is an information-disclosure issue in SimpleSAMLphp’s sanitycheck module. According to NVD, versions through 1.14.0 are affected and the issue was fixed starting in 1.14.1. A remote attacker could learn the PHP version on the system through unspecified vectors, which primarily affects confidentiality rather than integrity or availability.