Known Vulnerabilities for Gosaml2 by Gosaml2 Project
Listed below are 2 of the newest known vulnerabilities associated with "Gosaml2" by "Gosaml2 Project".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-9096 json | Casdoor versions 2.362.0 and earlier do not enforce SAML assertion time bounds. The gosaml2 library reports all time-validati... | Not Provided | 2026-05-28 | 2026-06-02 |
| CVE-2026-9093 json | In Casdoor versions 2.362.0 and earlier, the SAML service provider implementation does not validate the AudienceRestriction e... | Not Provided | 2026-05-28 | 2026-06-02 |
| CVE-2023-26483 json | gosaml2 is a Pure Go implementation of SAML 2.0. SAML Service Providers using this library for SAML authentication support ar... | 5.3 - MEDIUM | 2023-03-03 | 2023-11-07 |
| CVE-2020-7731 json | This affects all versions <0.7.0 of package github.com/russellhaering/gosaml2. There is a crash on nil-pointer dereference ca... | 7.5 - HIGH | 2021-04-30 | 2023-03-10 |