GHSA-6929-8p9f-26jx

Suggest an improvement
Source
https://github.com/advisories/GHSA-6929-8p9f-26jx
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-6929-8p9f-26jx/GHSA-6929-8p9f-26jx.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-6929-8p9f-26jx
Aliases
Published
2026-07-02T20:25:56Z
Modified
2026-08-04T21:30:19Z
Severity
  • 8.7 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N CVSS Calculator
Summary
SimpleSAMLphp HTTP-Artifact TLS validator confusion allows cross-IdP authentication bypass
Details

Summary

SimpleSAMLphp's HTTP-Artifact receive path can treat an unsigned embedded SAML Response as cryptographically valid for the wrong IdP.

In the HTTPArtifact::receive() flow, the SOAP ArtifactResponse receives a TLS-based validator from SOAPClient::addSSLValidator(). The embedded SAML Response then receives a validator that delegates signature validation to that outer ArtifactResponse. Later, the SP validates the embedded Response against metadata selected from the embedded response issuer, not necessarily the artifact issuer.

The critical issue is that SOAPClient::validateSSL() returns normally when the TLS public key does not match the key currently being validated. SAML2\Message::validate() treats any validator call that does not throw an exception as successful. As a result, an ArtifactResponse obtained from one IdP can validate an unsigned embedded SAML Response that claims to be issued by a different IdP.

In a multi-IdP/federation deployment where a malicious or lower-trust IdP can issue an HTTP-Artifact response to an SP, this can allow the attacker to authenticate to the SP as arbitrary users from a higher-trust victim IdP.

Impact

A malicious or lower-trust IdP in the same SP/federation trust set can authenticate to the SP as users from another IdP when HTTP-Artifact is used. The attacker can choose assertion attributes, NameID, and session data in the forged unsigned assertion.

This is an authentication bypass and identity-provider impersonation issue. In realistic federations, the security boundary between IdPs matters: a compromised or low-assurance IdP should not be able to mint identities for a high-assurance IdP.

Database specific
{
    "cwe_ids":  [
        "CWE-295"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-07-02T20:25:56Z",
    "nvd_published_at":  null,
    "severity":  "HIGH"
}
References

Affected packages

Packagist
simplesamlphp/saml2

Package

Name
simplesamlphp/saml2
Purl
pkg:composer/simplesamlphp/saml2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.0.0
Fixed
6.2.1

Affected versions

v6.*
v6.0.0
v6.0.1
v6.1.0
v6.1.1
v6.1.2
v6.1.3
v6.1.4
v6.1.5
v6.1.6
v6.2.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-6929-8p9f-26jx/GHSA-6929-8p9f-26jx.json"
simplesamlphp/saml2

Package

Name
simplesamlphp/saml2
Purl
pkg:composer/simplesamlphp/saml2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.0.0
Fixed
5.0.6

Affected versions

v5.*
v5.0.0
v5.0.1
v5.0.2
v5.0.3
v5.0.4
v5.0.5

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-6929-8p9f-26jx/GHSA-6929-8p9f-26jx.json"
simplesamlphp/saml2

Package

Name
simplesamlphp/saml2
Purl
pkg:composer/simplesamlphp/saml2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.20.0
Fixed
4.20.2

Affected versions

v4.*
v4.20.0
v4.20.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-6929-8p9f-26jx/GHSA-6929-8p9f-26jx.json"
simplesamlphp/saml2-legacy

Package

Name
simplesamlphp/saml2-legacy
Purl
pkg:composer/simplesamlphp/saml2-legacy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.20.0
Fixed
4.20.2

Affected versions

v4.*
v4.20.0
v4.20.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-6929-8p9f-26jx/GHSA-6929-8p9f-26jx.json"
simplesamlphp/saml2

Package

Name
simplesamlphp/saml2
Purl
pkg:composer/simplesamlphp/saml2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
4.19.3

Affected versions

v0.*
v0.1.0-alpha
v0.1.0
v0.3.0
v0.4.0
v0.4.1
v0.4.2
v0.5.0
v0.6.0
v0.6.1
v0.6.2
v0.6.3
v0.6.4
v0.7.0
v0.7.1
v0.8.0
v0.8.1
v1.*
v1.0.0
v1.1.0
v1.2.0
v1.3.0
v1.3.1
v1.3.2
v1.4.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.6.0
v1.6.1
v1.7.0
v1.7.1
v1.7.2
v1.8
v1.8.1
v1.8.2
v1.9
v1.9.1
v1.9.2
v1.10
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.10.5
v1.10.6
v2.*
v2.0.0
v2.0.1
v2.1
v2.2
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v3.*
v3.0.0
v3.0.1
v3.0.2
v3.0.3
v3.1.0
v3.1.1
v3.1.2
v3.1.3
v3.1.4
v3.1.5
v3.1.6
v3.2
v3.2.1
v3.2.2
v3.2.3
v3.2.4
v3.2.5
v3.2.6
v3.3.0
v3.3.1
v3.3.2
v3.3.3
v3.3.4
v3.3.5
v3.3.6
v3.3.7
v3.3.8
v3.3.9
v3.3.10
v3.3.11
v3.4.0
v3.4.1
v3.4.2
v3.4.3
v3.4.4
v3.4.5
v4.*
v4.0.0
v4.0.1
v4.0.2
v4.0.3
v4.1.0
v4.1.1
v4.1.2
v4.1.3
v4.1.4
v4.1.5
v4.1.6
v4.1.7
v4.1.8
v4.1.9
v4.1.10
v4.1.11
v4.1.12
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.2.5
v4.2.6
v4.2.7
v4.2.8
v4.3.0
v4.3.1
v4.4.0
v4.4.1
v4.5.0
v4.5.1
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.14
v4.6.15
v4.6.16
v4.16.14
v4.17.0
v4.18.0
v4.18.1
v4.19.0
v4.19.1
v4.19.2
4.*
4.6.9

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-6929-8p9f-26jx/GHSA-6929-8p9f-26jx.json"
simplesamlphp/saml2-legacy

Package

Name
simplesamlphp/saml2-legacy
Purl
pkg:composer/simplesamlphp/saml2-legacy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
4.19.3

Affected versions

v0.*
v0.1.0-alpha
v0.1.0
v0.3.0
v0.4.0
v0.4.1
v0.4.2
v0.5.0
v0.6.0
v0.6.1
v0.6.2
v0.6.3
v0.6.4
v0.7.0
v0.7.1
v0.8.0
v0.8.1
v1.*
v1.0.0
v1.1.0
v1.2.0
v1.3.0
v1.3.1
v1.3.2
v1.4.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.6.0
v1.6.1
v1.7.0
v1.7.1
v1.7.2
v1.8
v1.8.1
v1.8.2
v1.9
v1.9.1
v1.9.2
v1.10
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.10.5
v1.10.6
v2.*
v2.0.0
v2.0.1
v2.1
v2.2
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v3.*
v3.0.0
v3.0.1
v3.0.2
v3.0.3
v3.1.0
v3.1.1
v3.1.2
v3.1.3
v3.1.4
v3.1.5
v3.1.6
v3.2
v3.2.1
v3.2.2
v3.2.3
v3.2.4
v3.2.5
v3.2.6
v3.3.0
v3.3.1
v3.3.2
v3.3.3
v3.3.4
v3.3.5
v3.3.6
v3.3.7
v3.3.8
v3.3.9
v3.3.10
v3.3.11
v3.4.0
v3.4.1
v3.4.2
v3.4.3
v4.*
v4.0.0
v4.0.1
v4.0.2
v4.0.3
v4.1.0
v4.1.1
v4.1.2
v4.1.3
v4.1.4
v4.1.5
v4.1.6
v4.1.7
v4.1.8
v4.1.9
v4.1.10
v4.1.11
v4.1.12
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.2.5
v4.2.6
v4.2.7
v4.2.8
v4.3.0
v4.3.1
v4.4.0
v4.4.1
v4.5.0
v4.5.1
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.14
v4.6.15
v4.6.16
v4.16.14
v4.17.0
v4.18.0
v4.18.1
v4.19.0
v4.19.1
v4.19.2
4.*
4.6.9

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-6929-8p9f-26jx/GHSA-6929-8p9f-26jx.json"