PatchSiren

simplesamlphp CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH simplesamlphp CVE published 2026-08-19

CVE-2026-49289

A vulnerability in the SimpleSAMLphp SAML2 library permits attacker-controlled XPath transforms, potentially allowing a remote unauthenticated attacker to deny service to any entity relying on SimpleSAMLphp or directly on the SAML2 library. This issue affects versions 4.19.2 and 4.20.2, and is fixed in versions 4.19.3 and 4.20.3. Entities using SimpleSAMLphp or the SAML2 library should assess their exposu [truncated]

HIGH simplesamlphp CVE published 2026-08-19

CVE-2026-49283

The SimpleSAMLphp SAML2 library is vulnerable to an issue where an unsigned embedded SAML Response can be treated as cryptographically valid for the wrong identity provider, allowing for authentication as arbitrary users with attacker-chosen assertion attributes, NameID, and session data in a multi-IdP federation. This issue arises from improper validation in the HTTPArtifact::receive() flow, specifically [truncated]

HIGH simplesamlphp CVE published 2026-07-17

CVE-2026-49284

CVE-2026-49284 is an information disclosure vulnerability in SimpleSAMLphp versions before 1.18.6. The vulnerability occurs when the SAML SP ACS path does not enforce the IdP selected for an SP-initiated login when unsigned Response/InResponseTo is combined with a signed assertion lacking SubjectConfirmationData/InResponseTo. This issue allows a response issued by one trusted IdP to be bound to SP state c [truncated]

MEDIUM simplesamlphp CVE published 2026-05-18

CVE-2025-65954

CVE-2025-65954 affects SimpleSAMLphp-casserver, a CAS 1.0/2.0 compliant CAS server module for SimpleSAMLphp. In affected versions below 6.3.1 and 7.0.0, the logout endpoint accepts a url query parameter and treats it as trusted. Depending on configuration, the browser is redirected to that URL or shown a logout page with a follow-on link. The issue is fixed in versions 6.3.1 and 7.0.0.

CRITICAL Simplesamlphp CVE published 2017-02-17

CVE-2016-9814

CVE-2016-9814 is a critical authentication flaw in SimpleSAMLphp and the simplesamlphp/saml2 library. The issue is in validateSignature, where improper conversion of return values to boolean can let a remote attacker spoof SAML responses and may also trigger denial of service through memory consumption.

MEDIUM Simplesamlphp CVE published 2017-02-07

CVE-2016-3124

CVE-2016-3124 is an information-disclosure issue in SimpleSAMLphp’s sanitycheck module. According to NVD, versions through 1.14.0 are affected and the issue was fixed starting in 1.14.1. A remote attacker could learn the PHP version on the system through unspecified vectors, which primarily affects confidentiality rather than integrity or availability.