VYPR

simplesamlphp

by Debian

Source repositories

CVEs (1)

  • CVE-2026-49284Jul 19, 2026
    risk 0.00cvss epss 0.00

    SimpleSAMLphp versions before 1.18.6 contain an information disclosure vulnerability. Prior to 2.4.7 and 2.5.2, SimpleSAMLphp's SAML SP ACS path does not enforce the IdP selected for an SP-initiated login when unsigned Response/InResponseTo is combined with a signed assertion…