CVE-2023-36661: Debian Linux

High severity, CVSS 7.5. EPSS: 2.9% chance of exploitation in the next 30 days.

Shibboleth XMLTooling before 3.2.4, as used in OpenSAML and Shibboleth Service Provider, allows SSRF via a crafted KeyInfo element. (This is fixed in, for example, Shibboleth Service Provider 3.4.1.3 on Windows.)

Affected products

  • Debian Debian Linux: version 11.0 only; version 12.0 only
  • Shibboleth Xmltooling: before 3.2.4 (fixed in 3.2.4)

Published 2023-06-25. Last modified 2026-06-17.