CVE-2026-49289

Source
https://cve.org/CVERecord?id=CVE-2026-49289
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-49289.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-49289
Aliases
Downstream
Published
2026-08-19T14:48:52Z
Modified
2026-08-21T03:46:48Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
SimpleSAMLphp SAML2: Possible DoS via XPath Transform
Details

The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. In 4.19.2 and 4.20.2, the library permits attacker-controlled XPath transforms while processing XML signatures in specially crafted SAML messages. XPath evaluation can consume uncontrolled processing resources, allowing a remote unauthenticated attacker to deny service to any entity relying on SimpleSAMLphp or directly on the SAML2 library. The mitigation limits the number of transforms, permits only transform algorithms identified by the SAML 2.0 Core specification, and specifically rejects XPath transforms. This issue is fixed in versions 4.19.3 and 4.20.3.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-400"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/49xxx/CVE-2026-49289.json"
}
References

Affected packages

Git / github.com/simplesamlphp/saml2

Affected ranges

Type
GIT
Repo
https://github.com/simplesamlphp/saml2
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "4.19.2"
        },
        {
            "fixed": "4.19.3"
        },
        {
            "introduced": "4.20.2"
        },
        {
            "fixed": "4.20.3"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

v4.*
v4.19.2
v4.20.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-49289.json"