VYPR
High severity7.5NVD Advisory· Published Apr 27, 2021· Updated Jun 17, 2026

CVE-2021-31826

CVE-2021-31826

Description

Shibboleth Service Provider 3.x before 3.2.2 is prone to a NULL pointer dereference flaw involving the session recovery feature. The flaw is exploitable (for a daemon crash) on systems not using this feature if a crafted cookie is supplied.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • cpe:2.3:a:shibboleth:service_provider:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:shibboleth:service_provider:*:*:*:*:*:*:*:*range: >=3.0.0,<3.2.2
    • (no CPE)range: <3.2.2
  • Shibboleth/Service Providerdescription
  • Range: <3.2.2

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.