Known Vulnerabilities for Service Provider by Shibboleth
Listed below are 7 of the newest known vulnerabilities associated with "Service Provider" by "Shibboleth".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-94612 json | authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, an authentik SAML Source verifies a... | Not Provided | 2026-09-24 | 2026-09-24 |
| CVE-2026-90452 json | Requests from the reverse proxy to the identity-provider service for token discovery, introspection, and credential exchange ... | Not Provided | 2026-09-11 | 2026-10-02 |
| CVE-2026-89139 json | Temporal Server compiles a Worker Controller Instance module into its Worker Service, and that module registers a compute pro... | Not Provided | 2026-09-21 | 2026-09-21 |
| CVE-2026-88877 json | Traefik is a HTTP reverse proxy and load balancer. In versions >= v3.7.0 and <= v3.7.11, the Kubernetes ingress-nginx provide... | Not Provided | 2026-09-10 | 2026-09-10 |
| CVE-2026-86084 json | n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the public OIDC login and callback... | Not Provided | 2026-09-08 | 2026-09-09 |
| CVE-2026-86059 json | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy organization members without Git pro... | Not Provided | 2026-09-22 | 2026-09-22 |
| CVE-2026-85594 json | Traefik versions from v3.7.1 fail to enforce crossProviderNamespaces restrictions on the traefik.ingress.kubernetes.io/servic... | Not Provided | 2026-09-04 | 2026-09-08 |
| CVE-2026-82968 json | A flaw was found in the first-broker-login flow of the Keycloak identity management service. When a user links a social ident... | Not Provided | 2026-09-02 | 2026-09-02 |
| CVE-2026-81914 json | Apache Airflow's Google provider built Google Drive search expressions by interpolating file and folder names directly into s... | Not Provided | 2026-09-29 | 2026-09-29 |
| CVE-2026-79767 json | Gardener implements the automated management and operation of Kubernetes clusters as a service. Prior to 1.142.6, 1.143.3, 1.... | Not Provided | 2026-09-22 | 2026-09-23 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Shibboleth | Service Provider | 3.1.0 | |||
| Application | Shibboleth | Service Provider | 3.0.4 | |||
| Application | Shibboleth | Service Provider | 3.0.3 | |||
| Application | Shibboleth | Service Provider | 3.0.2 | |||
| Application | Shibboleth | Service Provider | 3.0.0 | |||
| Application | Shibboleth | Service Provider | 2.0 |