High severity7.5NVD Advisory· Published Apr 27, 2021· Updated Jun 17, 2026
CVE-2021-31826
CVE-2021-31826
Description
Shibboleth Service Provider 3.x before 3.2.2 is prone to a NULL pointer dereference flaw involving the session recovery feature. The flaw is exploitable (for a daemon crash) on systems not using this feature if a crafted cookie is supplied.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:shibboleth:service_provider:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:shibboleth:service_provider:*:*:*:*:*:*:*:*range: >=3.0.0,<3.2.2
- (no CPE)range: <3.2.2
- Shibboleth/Service Providerdescription
- Range: <3.2.2
Patches
Vulnerability mechanics
References
5- issues.shibboleth.net/jira/browse/SSPCPP-927nvdExploitPatchVendor Advisory
- bugs.debian.org/987608nvdMailing ListThird Party Advisory
- shibboleth.net/community/advisories/secadv_20210426.txtnvdVendor Advisory
- www.debian.org/security/2021/dsa-4905nvdThird Party Advisory
- git.shibboleth.net/view/nvd
News mentions
0No linked articles in our index yet.