CVE-2025-27773

CVSS 3.1 Score 8.6 of 10 (high)

Details

Published Mar 11, 2025
CWE ID 347

Summary

CVE-2025-27773 is a signature confusion vulnerability affecting the SimpleSAMLphp SAML2 library before versions 4.17.0 and 5.0.0-alpha.20. This PHP library is used for SAML2 functionality. The issue lies in the HTTPRedirect binding, where an attacker with a signed SAMLResponse can trick the application into accepting an unsigned message, bypassing security checks. The flaw has been addressed in versions 4.17.0 and 5.0.0-alpha.20 with the implementation of a fix.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share