Known Vulnerabilities for Saml2 by Sustainsys
Listed below are 2 of the newest known vulnerabilities associated with "Saml2" by "Sustainsys".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-44394 json | An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not propag... | Not Provided | 2026-05-28 | 2026-05-28 |
| CVE-2026-41005 json | Cloud Foundry UAA incorrectly treated XML encryption to the Service Provider (confidentiality) as a substitute for XML signat... | Not Provided | 2026-06-11 | 2026-06-11 |
| CVE-2026-40988 json | An application using spring-security-saml2-service-provider and the REDIRECT binding for SAML 2.0 Login or Logout may be vuln... | Not Provided | 2026-06-10 | 2026-06-27 |
| CVE-2026-18108 json | Net::SAML2 versions before 0.86 for Perl allow authentication bypass because _verify_encrypted_assertion accepts an Encrypted... | Not Provided | 2026-08-03 | 2026-08-03 |
| CVE-2026-18092 json | Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass via XML signature wrapping because new_from_xml rea... | Not Provided | 2026-08-03 | 2026-08-03 |
| CVE-2026-18089 json | Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass by verifying responses against the response-embedde... | Not Provided | 2026-08-03 | 2026-08-03 |
| CVE-2026-9487 json | XML::Sig versions before 0.71 for Perl allow signature wrapping via duplicate ID. _get_signed_xml() in lib/XML/Sig.pm, calle... | Not Provided | 2026-08-03 | 2026-08-03 |
| CVE-2022-45597 json | ComponentSpace.Saml2 4.4.0 Missing SSL Certificate Validation. NOTE: the vendor does not consider this a vulnerability becaus... | Not Provided | 2023-03-24 | 2026-07-09 |
| CVE-2020-5268 json | In Saml2 Authentication Services for ASP.NET versions before 1.0.2, and between 2.0.0 and 2.6.0, there is a vulnerability in ... | 7.3 - HIGH | 2020-04-21 | 2020-05-06 |
| CVE-2020-5261 json | Saml2 Authentication services for ASP.NET (NuGet package Sustainsys.Saml2) greater than 2.0.0, and less than version 2.5.0 ha... | 6.8 - MEDIUM | 2020-03-25 | 2021-03-24 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Sustainsys | Saml2 | 2.7.0 | |||
| Application | Sustainsys | Saml2 | 2.6.0 | |||
| Application | Sustainsys | Saml2 | 2.5.0 | |||
| Application | Sustainsys | Saml2 | 2.4.0 | |||
| Application | Sustainsys | Saml2 | 2.3.0 | |||
| Application | Sustainsys | Saml2 | 2.2.0 | |||
| Application | Sustainsys | Saml2 | 2.1.0 | |||
| Application | Sustainsys | Saml2 | 2.0.0 | |||
| Application | Sustainsys | Saml2 | 1.0.2 | |||
| Application | Sustainsys | Saml2 | 1.0.1 | |||
| Application | Sustainsys | Saml2 | 1.0.0 | |||
| Application | Sustainsys | Saml2 | 0.9.0 | |||
| Application | Sustainsys | Saml2 | 0.8.0 | |||
| Application | Sustainsys | Saml2 | 0.7.2 | |||
| Application | Sustainsys | Saml2 | 0.7.0 | |||
| Application | Sustainsys | Saml2 | 0.6.2 | |||
| Application | Sustainsys | Saml2 | 0.6.0 | |||
| Application | Sustainsys | Saml2 | 0.5.2 | |||
| Application | Sustainsys | Saml2 | 0.5.0 | |||
| Application | Sustainsys | Saml2 | 0.4.0 |