VYPR

Gosaml2

by Gosaml2 Project

Source repositories

CVEs (2)

  • CVE-2020-7731HigApr 30, 2021
    risk 0.42cvss 7.5epss 0.02

    This affects all versions <0.7.0 of package github.com/russellhaering/gosaml2. There is a crash on nil-pointer dereference caused by sending malformed XML signatures.

  • CVE-2023-26483MedMar 3, 2023
    risk 0.28cvss 5.3epss 0.01

    gosaml2 is a Pure Go implementation of SAML 2.0. SAML Service Providers using this library for SAML authentication support are likely susceptible to Denial of Service attacks. A bug in this library enables attackers to craft a `deflate`-compressed request which will consume…