High severityNVD Advisory· Published Jul 2, 2026
SimpleSAMLphp has Possible DoS via XPath Transform
CVE-2026-49289
Description
Summary
This library turned out to be vulnerable to Denial-of-Service attacks using XPath transforms. A mitigation has been put in place to restrict the number of transforms and to restrict transforms to only the transform-algorithms mentioned in the SAML 2.0 Core Specifications (and specifically refuse XPath transforms).
Impact
An attacker is able to send specially crafted messages to any entity relying on SimpleSAMLphp (or directly on this SAML2-library) to be able to perform a Denial-of-Service attack.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
simplesamlphp/saml2Packagist | < 4.20.3 | 4.20.3 |
simplesamlphp/saml2-legacyPackagist | < 4.20.3 | 4.20.3 |
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.