Skip to main content

Vendor/product archive

samlify_project / samlify CVEs

Beta · best-effort

3 CVEs tagged to samlify_project / samlify1 Critical, 2 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2026-46490

Published Jun 8, 2026

samlify is a Node.js library for SAML single sign-on. Prior to version 2.13.0, samlify’s template substitution only escapes attribute contexts. Values inserted into element text (…

CVSS 8.7 · High
evidence mentions
1
Buzz score
16.9
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-47949

Published May 19, 2025

samlify is a Node.js library for SAML single sign-on. A Signature Wrapping attack has been found in samlify prior to version 2.10.0, allowing an attacker to forge a SAML Response…

CVSS 9.9 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2017-1000452

Published Jan 2, 2018

An XML Signature Wrapping vulnerability exists in Samlify 2.2.0 and earlier, and in predecessor Express-saml2 which could allow attackers to impersonate arbitrary users.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-3 of 3 CVEsPage 1 of 1