Known Vulnerabilities for products from Shibboleth

Listed below are 18 of the newest known vulnerabilities associated with the vendor "Shibboleth".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2026-12281 json Not Provided 2026-07-15 2026-07-15
CVE-2023-36661 json Shibboleth XMLTooling before 3.2.4, as used in OpenSAML and Shibboleth Service Provider, allows SSRF via a crafted KeyInfo el... 7.5 - HIGH 2023-06-25 2023-07-06
CVE-2023-22947 json ** DISPUTED ** Insecure folder permissions in the Windows installation path of Shibboleth Service Provider (SP) before 3.4.1 ... 7.3 - HIGH 2023-01-11 2023-11-07
CVE-2022-24129 json The OIDC OP plugin before 3.0.4 for Shibboleth Identity Provider allows server-side request forgery (SSRF) due to insufficien... 8.2 - HIGH 2022-02-04 2022-02-09
CVE-2021-31826 json Shibboleth Service Provider 3.x before 3.2.2 is prone to a NULL pointer dereference flaw involving the session recovery featu... 7.5 - HIGH 2021-04-27 2023-11-07
CVE-2021-28963 json Shibboleth Service Provider before 3.2.1 allows content injection because template generation uses attacker-controlled parame... 5.3 - MEDIUM 2021-03-22 2023-11-07
CVE-2020-27978 json Shibboleth Identify Provider 3.x before 3.4.6 has a denial of service flaw. A remote unauthenticated attacker can cause a log... 7.5 - HIGH 2020-10-28 2022-02-08
CVE-2019-19191 json Shibboleth Service Provider (SP) 3.x before 3.1.0 shipped a spec file that calls chown on files in a directory controlled by ... 7.8 - HIGH 2019-11-21 2020-01-14
CVE-2018-0489 json Shibboleth XMLTooling-C before 1.6.4, as used in Shibboleth Service Provider before 2.6.1.4 on Windows and other products, mi... 6.5 - MEDIUM 2018-02-27 2018-03-23
CVE-2018-0486 json Shibboleth XMLTooling-C before 1.6.3, as used in Shibboleth Service Provider before 2.6.0 on Windows and other products, mish... 6.5 - MEDIUM 2018-01-13 2018-02-15
CVE-2017-16853 json The DynamicMetadataProvider class in saml/saml2/metadata/impl/DynamicMetadataProvider.cpp in OpenSAML-C in OpenSAML before 2.... Not Provided 2017-11-16 2025-04-20
CVE-2017-16852 json shibsp/metadata/DynamicMetadataProvider.cpp in the Dynamic MetadataProvider plugin in Shibboleth Service Provider before 2.6.... Not Provided 2017-11-16 2025-04-20
CVE-2015-2684 json Shibboleth Service Provider (SP) before 2.5.4 allows remote authenticated users to cause a denial of service (crash) via a cr... Not Provided 2015-03-31 2026-05-06
CVE-2015-1796 json The PKIX trust engines in Shibboleth Identity Provider before 2.4.4 and OpenSAML Java (OpenSAML-J) before 2.6.5 trust candida... Not Provided 2015-07-08 2026-05-06
CVE-2014-3603 json The (1) HttpResource and (2) FileBackedHttpResource implementations in Shibboleth Identity Provider (IdP) before 2.4.1 and Op... 5.9 - MEDIUM 2019-04-04 2019-04-08
CVE-2013-6440 json The (1) BasicParserPool, (2) StaticBasicParserPool, (3) XML Decrypter, and (4) SAML Decrypter in Shibboleth OpenSAML-Java bef... Not Provided 2014-02-14 2026-04-29
CVE-2011-2516 json Off-by-one error in the XML signature feature in Apache XML Security for C++ 1.6.0, as used in Shibboleth before 2.4.3 and po... Not Provided 2011-07-11 2026-04-29
CVE-2011-1411 json Shibboleth OpenSAML library 2.4.x before 2.4.3 and 2.5.x before 2.5.1, and IdP before 2.3.2, allows remote attackers to forge... Not Provided 2011-09-02 2026-04-29
CVE-2010-2450 json The keygen.sh script in Shibboleth SP 2.0 (located in /usr/local/etc/shibboleth by default) uses OpenSSL to create a DES priv... 7.5 - HIGH 2019-11-07 2019-11-13

Known software with vulnerabilities from Shibboleth

Type Vendor Product Version
ApplicationShibbolethIdentify Provider3.0.0
ApplicationShibbolethIdentity Provider2.4.3
ApplicationShibbolethOpensaml2.6.1
ApplicationShibbolethOpensaml Java2.6.4
ApplicationShibbolethService Provider2.0
ApplicationShibbolethShibboleth-sp1.3.1

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report