Executive brief
Samly is a library used by applications to authenticate users via SAML 2.0, a widely-used enterprise single sign-on protocol. A flaw in Samly fails to prevent reuse of valid SAML authentication assertions, allowing an attacker who captures a legitimate authentication response (from network traffic, browser history, or logs) to replay it multiple times to establish fraudulent sessions as the original user until the assertion expires. This could enable account takeover and unauthorized access to protected applications.
Technical details
Samly.Helper.decode_idp_auth_resp/3 validates SAML assertions by calling esaml_sp:validate_assertion/2, but fails to enforce the SAML 2.0 Web Browser SSO Profile requirement that bearer assertions be used exactly once. While esaml provides a validate_assertion/3 arity that accepts a DuplicateFun parameter to detect replay attacks, Samly never invokes this function and offers no configuration option to supply a duplicate detector. An attacker with access to a valid SAMLResponse (captured from the network, browser history, or application logs) can repeatedly submit the identical bytes to establish new authenticated sessions as the assertion subject, with successful replays possible until the assertion's NotOnOrAfter timestamp expires. No patch status is indicated in the advisory.
Affected products
- Samly Samly 0.3.0 and later
Timeline
- 2026-08-20: disclosed