CVE-2024-52596: Simplesamlphp XML-Common
High severity, CVSS 8.8. EPSS: 1% chance of exploitation in the next 30 days.
SimpleSAMLphp xml-common is a common classes for handling XML-structures. When loading an (untrusted) XML document, for example the SAMLResponse, it's possible to induce an XXE. This vulnerability is fixed in 1.19.0.
Affected products
- Simplesamlphp XML-Common: before 1.20.0 (fixed in 1.20.0)
Published 2024-12-02. Last modified 2026-06-17.