CVE-2017-1000246: PYSAML2 Project PYSAML2

Medium severity, CVSS 5.3. EPSS: 0.9% chance of exploitation in the next 30 days.

Python package pysaml2 version 4.4.0 and earlier reuses the initialization vector across encryptions in the IDP server, resulting in weak encryption of data.

Affected products

Published 2017-11-17. Last modified 2026-06-17.