PT-2026-55454 · Git+4 · Saml2+3

CVE-2026-49289

·

Published

2026-07-02

·

Updated

2026-08-28

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions SimpleSAMLphp versions 4.19.2 through 4.19.2 SimpleSAMLphp versions 4.20.2 through 4.20.2
Description The SAML2 library permits attacker-controlled XPath transforms during the processing of XML signatures in specially crafted SAML messages. XPath evaluation can consume uncontrolled processing resources, enabling a remote unauthenticated attacker to cause a denial of service to any entity relying on the library.
Recommendations Update SimpleSAMLphp version 4.19.2 to 4.19.3. Update SimpleSAMLphp version 4.20.2 to 4.20.3.

Exploit

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-49289
GHSA-5CJR-MXJ5-WMRX

Affected Products

Saml2
Simplesamlphp
Simplesamlphp/Saml2
Simplesamlphp/Saml2-Legacy