Feed/CVE-2026-49289
CVE-2026-49289HIGHCVSS 7.5

SimpleSAMLphp has Possible DoS via XPath Transform

Published Jul 2, 2026·Updated Aug 19, 2026

NVD Description

## Summary This library turned out to be vulnerable to Denial-of-Service attacks using XPath transforms. A mitigation has been put in place to restrict the number of transforms and to restrict transforms to only the transform-algorithms mentioned in the SAML 2.0 Core Specifications (and specifically refuse XPath transforms). ## Impact An attacker is able to send specially crafted messages to any entity relying on SimpleSAMLphp (or directly on this SAML2-library) to be able to perform a Denial-of-Service attack.

Affected Packages (2)

simplesamlphp/saml2-legacyCOMPOSER
From 4.20.0
Fixed in = 4.20.2
simplesamlphp/saml2COMPOSER
From 4.20.0
Fixed in = 4.20.2

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free