CVE-2017-1000246: PYSAML2 Project PYSAML2
Medium severity, CVSS 5.3. EPSS: 0.9% chance of exploitation in the next 30 days.
Python package pysaml2 version 4.4.0 and earlier reuses the initialization vector across encryptions in the IDP server, resulting in weak encryption of data.
Affected products
- PYSAML2 Project PYSAML2: before 4.6.0 (fixed in 4.6.0)
Published 2017-11-17. Last modified 2026-06-17.