Skip to main content

Vendor/product archive

timlegge / net::saml2 CVEs

Beta · best-effort

3 CVEs tagged to timlegge / net::saml21 Critical, 2 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2026-18108

Published Aug 3, 2026

Net::SAML2 versions before 0.86 for Perl allow authentication bypass because _verify_encrypted_assertion accepts an EncryptedAssertion whose decrypted content carries no signature…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2026-18092

Published Aug 3, 2026

Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass via XML signature wrapping because new_from_xml reads assertion identity with document-wide XPath instead…

CVSS 8.1 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-18089

Published Aug 3, 2026

Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass by verifying responses against the response-embedded certificate in verify_xml when no trust anchor is co…

CVSS 7.5 · High
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort
Showing 1-3 of 3 CVEsPage 1 of 1