CVE-2026-49289

NameCVE-2026-49289
DescriptionThe SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. In 4.19.2 and 4.20.2, the library permits attacker-controlled XPath transforms while processing XML signatures in specially crafted SAML messages. XPath evaluation can consume uncontrolled processing resources, allowing a remote unauthenticated attacker to deny service to any entity relying on SimpleSAMLphp or directly on the SAML2 library. The mitigation limits the number of transforms, permits only transform algorithms identified by the SAML 2.0 Core specification, and specifically rejects XPath transforms. This issue is fixed in versions 4.19.3 and 4.20.3.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
simplesamlphp (PTS)bookworm1.19.7-1+deb12u2vulnerable
bookworm (security)1.19.7-1+deb12u1vulnerable
forky, sid2.5.3.1-1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
simplesamlphpsource(unstable)(unfixed)

Notes

[bookworm] - simplesamlphp <postponed> (Minor issue; low popcon)
[bullseye] - simplesamlphp <postponed> (Minor issue; low popcon)
https://github.com/simplesamlphp/saml2/security/advisories/GHSA-5cjr-mxj5-wmrx
Fixed by: https://github.com/simplesamlphp/saml2/commit/0043033891fdba9618386ab583e1d8afdf8aea6e (v4.20.3)
Fixed by: https://github.com/simplesamlphp/saml2/commit/6695eb923da491f716009c2a26b34a463ac05c6b (v4.19.3)

Search for package or bug name: Reporting problems