CVE-2018-6519: Debian Linux

High severity, CVSS 7.5. EPSS: 1.7% chance of exploitation in the next 30 days.

The SAML2 library before 1.10.4, 2.x before 2.3.5, and 3.x before 3.1.1 in SimpleSAMLphp has a Regular Expression Denial of Service vulnerability for fraction-of-seconds data in a timestamp.

Affected products

  • Debian Debian Linux: version 8.0 only; version 9.0 only
  • Simplesamlphp SAML2: from 1.0.0, before 1.10.4 (fixed in 1.10.4); from 2.0.0, before 2.3.5 (fixed in 2.3.5); from 3.0.0, before 3.1.1 (fixed in 3.1.1)

Published 2018-02-02. Last modified 2026-06-17.