Executive brief
SimpleSAMLphp, a library used for single sign-on (SSO) authentication, is vulnerable to a denial-of-service attack. An attacker can send specially crafted messages that overwhelm the system, potentially causing the authentication service to become unavailable to legitimate users. This could disrupt access to corporate applications and services that rely on this library for user logins.
Technical details
A Denial-of-Service (DoS) vulnerability exists in the SimpleSAMLphp saml2 library due to uncontrolled resource consumption during the processing of XPath transforms. The library failed to properly restrict the number and type of XML transforms allowed in SAML messages. A remote, unauthenticated attacker can exploit this by sending specially crafted SAML messages containing complex XPath transforms, leading to CPU or memory exhaustion (CWE-400). The issue has been mitigated in version 4.20.3 by restricting transform algorithms to those defined in the SAML 2.0 Core Specifications and explicitly disabling XPath transforms.
Affected products
- SimpleSAMLphp saml2 <= 4.20.2
- SimpleSAMLphp saml2-legacy <= 4.20.2
Timeline
- 2026-05-29: disclosed: Advisory published by maintainers
- 2026-07-02: advisory: GitHub Advisory Database entry published
- 2026-05-29: patched: Version 4.20.3 released
References
- https://api.github.com/users/ahacker1-securesaml
- https://github.com/ahacker1-securesaml
- https://api.github.com/users/ahacker1-securesaml/gists%7B/gist_id%7D
- https://api.github.com/users/ahacker1-securesaml/repos
- https://avatars.githubusercontent.com/u/180476984?v=4
- https://api.github.com/users/ahacker1-securesaml/events%7B/privacy%7D