A Signature Wrapping attack has been found in samlify <v2.10.0, allowing an attacker to forge a SAML Response to authenticate as any user. An attacker would need a signed XML document by the identity provider.
{
"cwe_ids": [
"CWE-347"
],
"github_reviewed": true,
"github_reviewed_at": "2025-05-19T22:33:00Z",
"nvd_published_at": "2025-05-19T20:15:26Z",
"severity": "CRITICAL"
}