Junglewise Threat Intelligence

CVE-2026-28809: esaml XXE vulnerability in SAML message parsing

CVE-2026-28809 · Severity: info · CVSS 6.3 · Published 2026-03-23

Executive brief

esaml is a library used to handle SAML authentication, which allows users to log into multiple services with one set of credentials. A security flaw allows an attacker to send a specially crafted message that forces the server to read sensitive local files, such as system secrets or configuration data. This information could then be leaked through system logs or error messages, potentially compromising the entire environment.

Technical details

The esaml library and its various forks (arekinath, handnot2, dropbox, Jump-App) are vulnerable to XML External Entity (XXE) injection. The vulnerability exists because the library uses the 'xmerl_scan:string/2' function to parse SAML messages before signature verification occurs, without explicitly disabling external entity expansion. On Erlang/OTP versions prior to 27, the Xmerl parser enables entity expansion by default. An unauthenticated remote attacker can exploit this by sending a malicious SAML document containing external entity references. This can lead to the disclosure of local files (such as Kubernetes secrets) if their contents are reflected in error logs or processed documents, or it can be used to perform SSRF. The issue is mitigated by upgrading to Erlang/OTP 27 or applying patches available for the Jump-App fork.

Affected products

  • Jump-App esaml <= 4.6.0
  • arekinath esaml <= 1.1
  • handnot2 esaml <= 4.2.0
  • dropbox esaml All versions

Timeline

  • 2026-03-23: disclosed
  • 2026-03-23: advisory
  • 2026-03-23: patched: Patch available for Jump-App fork; other forks may remain unpatched.

References