CVE-2025-27773: Simplesamlphp SAML2

High severity, CVSS 8.6. EPSS: 0.4% chance of exploitation in the next 30 days.

The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. Prior to versions 4.17.0 and 5.0.0-alpha.20, there is a signature confusion attack in the HTTPRedirect binding. An attacker with any signed SAMLResponse via the HTTP-Redirect binding can cause the application to accept an unsigned message. Versions 4.17.0 and 5.0.0-alpha.20 contain a fix for the issue.

Affected products

  • Simplesamlphp SAML2: before 4.17.0 (fixed in 4.17.0); from 5.0.0-alpha.1, before 5.0.0-alpha.20 (fixed in 5.0.0-alpha.20)

Published 2025-03-11. Last modified 2026-06-17.