CVE-2019-18632: Europa Eidas-Node Integration Package

Critical severity, CVSS 9.8. EPSS: 0.8% chance of exploitation in the next 30 days.

European Commission eIDAS-Node Integration Package before 2.3.1 allows Certificate Faking because an attacker can sign a manipulated SAML response with a forged certificate.

Affected products

  • Europa Eidas-Node Integration Package: before 2.3.1 (fixed in 2.3.1)

Published 2019-10-30. Last modified 2026-06-17.