Known Vulnerabilities for Saml2 by Simplesamlphp
Listed below are 6 of the newest known vulnerabilities associated with "Saml2" by "Simplesamlphp".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-44394 json | An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not propag... | Not Provided | 2026-05-28 | 2026-05-28 |
| CVE-2026-41005 json | Cloud Foundry UAA incorrectly treated XML encryption to the Service Provider (confidentiality) as a substitute for XML signat... | Not Provided | 2026-06-11 | 2026-06-11 |
| CVE-2026-40988 json | An application using spring-security-saml2-service-provider and the REDIRECT binding for SAML 2.0 Login or Logout may be vuln... | Not Provided | 2026-06-10 | 2026-06-27 |
| CVE-2026-18108 json | Net::SAML2 versions before 0.86 for Perl allow authentication bypass because _verify_encrypted_assertion accepts an Encrypted... | Not Provided | 2026-08-03 | 2026-08-03 |
| CVE-2026-18092 json | Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass via XML signature wrapping because new_from_xml rea... | Not Provided | 2026-08-03 | 2026-08-03 |
| CVE-2026-18089 json | Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass by verifying responses against the response-embedde... | Not Provided | 2026-08-03 | 2026-08-03 |
| CVE-2026-9487 json | XML::Sig versions before 0.71 for Perl allow signature wrapping via duplicate ID. _get_signed_xml() in lib/XML/Sig.pm, calle... | Not Provided | 2026-08-03 | 2026-08-03 |
| CVE-2023-49087 json | 7.5 - HIGH | 2023-11-30 | 2023-12-06 | |
| CVE-2023-41890 json | Sustainsys.Saml2 library adds SAML2P support to ASP.NET web sites, allowing the web site to act as a SAML2 Service Provider. ... | 7.5 - HIGH | 2023-09-19 | 2023-09-22 |
| CVE-2022-45597 json | ComponentSpace.Saml2 4.4.0 Missing SSL Certificate Validation. NOTE: the vendor does not consider this a vulnerability becaus... | 7.5 - HIGH | 2023-03-24 | 2026-07-09 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Simplesamlphp | Saml2 | 3.2.2 | |||
| Application | Simplesamlphp | Saml2 | 3.2.1 | |||
| Application | Simplesamlphp | Saml2 | 3.2 | |||
| Application | Simplesamlphp | Saml2 | 3.1.6 | |||
| Application | Simplesamlphp | Saml2 | 3.1.5 | |||
| Application | Simplesamlphp | Saml2 | 3.1.4 | |||
| Application | Simplesamlphp | Saml2 | 3.1.3 | |||
| Application | Simplesamlphp | Saml2 | 3.1.2 | |||
| Application | Simplesamlphp | Saml2 | 3.1.1 | |||
| Application | Simplesamlphp | Saml2 | 3.1.0 | |||
| Application | Simplesamlphp | Saml2 | 3.0.3 | |||
| Application | Simplesamlphp | Saml2 | 3.0.2 | |||
| Application | Simplesamlphp | Saml2 | 3.0.1 | |||
| Application | Simplesamlphp | Saml2 | 3.0.0 | |||
| Application | Simplesamlphp | Saml2 | 2.4.0 | |||
| Application | Simplesamlphp | Saml2 | 2.3.8 | |||
| Application | Simplesamlphp | Saml2 | 2.3.7 | |||
| Application | Simplesamlphp | Saml2 | 2.3.6 | |||
| Application | Simplesamlphp | Saml2 | 2.3.5 | |||
| Application | Simplesamlphp | Saml2 | 2.3.4 |