Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4161-1 | simplesamlphp security update |
EUVD |
EUVD-2025-7804 | The SimpleSAMLphp SAML2 library incorrectly verifies signatures for HTTP-Redirect binding |
Github GHSA |
GHSA-46r4-f8gj-xg56 | The SimpleSAMLphp SAML2 library incorrectly verifies signatures for HTTP-Redirect binding |
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 09 May 2025 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 11 Mar 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 11 Mar 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. Prior to versions 4.17.0 and 5.0.0-alpha.20, there is a signature confusion attack in the HTTPRedirect binding. An attacker with any signed SAMLResponse via the HTTP-Redirect binding can cause the application to accept an unsigned message. Versions 4.17.0 and 5.0.0-alpha.20 contain a fix for the issue. | |
| Title | SimpleSAMLphp SAML2 library has incorrect signature verification for HTTP-Redirect binding | |
| Weaknesses | CWE-347 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-05-09T20:03:38.107Z
Reserved: 2025-03-06T18:06:54.460Z
Link: CVE-2025-27773
Updated: 2025-05-09T20:03:38.107Z
Status : Deferred
Published: 2025-03-11T19:15:43.677
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-27773
No data.
OpenCVE Enrichment
Updated: 2025-07-12T15:26:09Z
Debian DLA
EUVD
Github GHSA