This update for shibboleth-sp fixes the following issue:
CVE-2025-9943: SQL injection in the 'ID' attribute of the SAML response when the replay cache of the Shibboleth
Service Provider (SP) is configured to use an SQL database as storage service (bsc#1249394).