CVE-2025-27773

HIGH

Simplesamlphp Saml2 < 4.17.0 - Signature Verification Bypass

Title source: rule
STIX 2.1

Description

The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. Prior to versions 4.17.0 and 5.0.0-alpha.20, there is a signature confusion attack in the HTTPRedirect binding. An attacker with any signed SAMLResponse via the HTTP-Redirect binding can cause the application to accept an unsigned message. Versions 4.17.0 and 5.0.0-alpha.20 contain a fix for the issue.

Scores

CVSS v3 8.6
EPSS 0.0019
EPSS Percentile 40.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-347
Status published
Products (4)
simplesamlphp/saml2 0 - 4.17.0Packagist
simplesamlphp/saml2 < 4.17.0
simplesamlphp/saml2 >= 5.0.0-alpha.1, < 5.0.0-alpha.20
simplesamlphp/saml2-legacy 0 - 4.17.0Packagist
Published Mar 11, 2025
Tracked Since Feb 18, 2026