VYPR
High severity7.5NVD Advisory· Published Feb 2, 2018· Updated Jun 17, 2026

CVE-2018-6519

CVE-2018-6519

Description

The SAML2 library before 1.10.4, 2.x before 2.3.5, and 3.x before 3.1.1 in SimpleSAMLphp has a Regular Expression Denial of Service vulnerability for fraction-of-seconds data in a timestamp.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
simplesamlphp/saml2Packagist
< 1.10.41.10.4
simplesamlphp/saml2Packagist
>= 2.0, < 2.3.52.3.5
simplesamlphp/saml2Packagist
>= 3.0, < 3.1.13.1.1

Affected products

4
  • cpe:2.3:a:simplesamlphp:saml2:*:*:*:*:*:*:*:*
    Range: >=1.0.0,<1.10.4
  • Debian/linux2 versions
    cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
    • cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
  • ghsa-coords
    Range: < 1.10.4

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.