<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 17:06:09 +0000</lastBuildDate>
    <item>
      <title>certfr-2025-avi-0836 — De multiples vulnérabilités ont été découvertes dans Tenable Security Center. Elles permettent à un attaquant de provoq…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0836</link>
      <description>certfr-2025-avi-0836</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0836</guid>
    </item>
    <item>
      <title>EUVD-2026-238779</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-238779</link>
      <description>EUVD-2026-238779</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-238779</guid>
    </item>
    <item>
      <title>fkie_cve-2025-27773</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-27773</link>
      <description>&lt;p&gt;The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. Prior to versions 4.17.0 and 5.0.0-alpha.20, there is a signature confusion attack in the HTTPRedirect binding. An attacker with any signed SAMLResponse via the HTTP-Redirect binding can cause the application to accept an unsigned message. Versions 4.17.0 and 5.0.0-alpha.20 contain a fix for the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. Prior to versions 4.17.0 and 5.0.0-alpha.20, there is a signature confusion attack in the HTTPRedirect binding. An attacker with any signed SAMLResponse via the HTTP-Redirect binding can cause the application to accept an unsigned message. Versions 4.17.0 and 5.0.0-alpha.20 contain a fix for the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-27773</guid>
    </item>
    <item>
      <title>GHSA-46r4-f8gj-xg56 — The SimpleSAMLphp SAML2 library incorrectly verifies signatures for HTTP-Redirect binding</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-46r4-f8gj-xg56</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: simplesamlphp/saml2, Packagist: simplesamlphp/saml2-legacy&lt;/p&gt;
&lt;p&gt;### Summary
There&amp;#39;s a signature confusion attack in the HTTPRedirect binding. An attacker with any signed SAMLResponse via the HTTP-Redirect binding can cause the application to accept an unsigned message.&lt;/p&gt;
&lt;p&gt;I believe that it exists for v4 only. I have not yet developed a PoC.&lt;/p&gt;
&lt;p&gt;V5 is well designed and instead builds the signed query from the same message that will be consumed.
### Details&lt;/p&gt;
&lt;p&gt;#### What is verified
The data[&amp;#39;SignedQuery&amp;#39;] is the string that will be verified by the public key.&lt;/p&gt;
&lt;p&gt;It is defined here:
https://github.com/simplesamlphp/saml2/blob/9545abd0d9d48388f2fa00469c5c1e0294f0303e/src/SAML2/HTTPRedirect.php#L178-L217&lt;/p&gt;
&lt;p&gt;THe code will iterate through each parameter name. Notably, sigQuery is overridden each time when processing, making the last of SAMLRequest/SAMLResponse used for sigQuery.&lt;/p&gt;
&lt;p&gt;For example, given:&lt;/p&gt;
&lt;p&gt;SAMLRequest=a&amp;amp;SAMLResponse=idpsigned&lt;/p&gt;
&lt;p&gt;SAMLResponse=idpsigned will be set as sigQuery, then later verified&lt;/p&gt;
&lt;p&gt;#### What is actually processed&lt;/p&gt;
&lt;p&gt;Processing uses SAMLRequest parameter value first, (if it exists) then SAMLResponse:&lt;/p&gt;
&lt;p&gt;https://github.com/simplesamlphp/saml2/blob/9545abd0d9d48388f2fa00469c5c1e0294f0303e/src/SAML2/HTTPRedirect.php#L104-L113&lt;/p&gt;
&lt;p&gt;Given this, the contents that are processed might not be the same as the data that is actually verified.&lt;/p&gt;
&lt;p&gt;### Exploiting
Suppose an attacker has a signed HTTP Redirect binding from IdP, say a signed logout response. :&lt;/p&gt;
&lt;p&gt;SAMLResponse=idpsigned&amp;amp;RelayState=...&amp;amp;SigAlg=...&amp;amp;Signature&lt;/p&gt;
&lt;p&gt;Then an attacker can append SAMLReq…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: simplesamlphp/saml2, Packagist: simplesamlphp/saml2-legacy&lt;/p&gt;
&lt;p&gt;### Summary
There&amp;#39;s a signature confusion attack in the HTTPRedirect binding. An attacker with any signed SAMLResponse via the HTTP-Redirect binding can cause the application to accept an unsigned message.&lt;/p&gt;
&lt;p&gt;I believe that it exists for v4 only. I have not yet developed a PoC.&lt;/p&gt;
&lt;p&gt;V5 is well designed and instead builds the signed query from the same message that will be consumed.
### Details&lt;/p&gt;
&lt;p&gt;#### What is verified
The data[&amp;#39;SignedQuery&amp;#39;] is the string that will be verified by the public key.&lt;/p&gt;
&lt;p&gt;It is defined here:
https://github.com/simplesamlphp/saml2/blob/9545abd0d9d48388f2fa00469c5c1e0294f0303e/src/SAML2/HTTPRedirect.php#L178-L217&lt;/p&gt;
&lt;p&gt;THe code will iterate through each parameter name. Notably, sigQuery is overridden each time when processing, making the last of SAMLRequest/SAMLResponse used for sigQuery.&lt;/p&gt;
&lt;p&gt;For example, given:&lt;/p&gt;
&lt;p&gt;SAMLRequest=a&amp;amp;SAMLResponse=idpsigned&lt;/p&gt;
&lt;p&gt;SAMLResponse=idpsigned will be set as sigQuery, then later verified&lt;/p&gt;
&lt;p&gt;#### What is actually processed&lt;/p&gt;
&lt;p&gt;Processing uses SAMLRequest parameter value first, (if it exists) then SAMLResponse:&lt;/p&gt;
&lt;p&gt;https://github.com/simplesamlphp/saml2/blob/9545abd0d9d48388f2fa00469c5c1e0294f0303e/src/SAML2/HTTPRedirect.php#L104-L113&lt;/p&gt;
&lt;p&gt;Given this, the contents that are processed might not be the same as the data that is actually verified.&lt;/p&gt;
&lt;p&gt;### Exploiting
Suppose an attacker has a signed HTTP Redirect binding from IdP, say a signed logout response. :&lt;/p&gt;
&lt;p&gt;SAMLResponse=idpsigned&amp;amp;RelayState=...&amp;amp;SigAlg=...&amp;amp;Signature&lt;/p&gt;
&lt;p&gt;Then an attacker can append SAMLReq…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-46r4-f8gj-xg56</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-27773</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-27773</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: simplesamlphp, Ubuntu:Pro:18.04:LTS: simplesamlphp, Ubuntu:Pro:20.04:LTS: simplesamlphp, Ubuntu:Pro:22.04:LTS: simplesamlphp, Ubuntu:24.04:LTS: simplesamlphp, Ubuntu:25.10: simplesamlphp&lt;/p&gt;
&lt;p&gt;The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. Prior to versions 4.17.0 and 5.0.0-alpha.20, there is a signature confusion attack in the HTTPRedirect binding. An attacker with any signed SAMLResponse via the HTTP-Redirect binding can cause the application to accept an unsigned message. Versions 4.17.0 and 5.0.0-alpha.20 contain a fix for the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: simplesamlphp, Ubuntu:Pro:18.04:LTS: simplesamlphp, Ubuntu:Pro:20.04:LTS: simplesamlphp, Ubuntu:Pro:22.04:LTS: simplesamlphp, Ubuntu:24.04:LTS: simplesamlphp, Ubuntu:25.10: simplesamlphp&lt;/p&gt;
&lt;p&gt;The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. Prior to versions 4.17.0 and 5.0.0-alpha.20, there is a signature confusion attack in the HTTPRedirect binding. An attacker with any signed SAMLResponse via the HTTP-Redirect binding can cause the application to accept an unsigned message. Versions 4.17.0 and 5.0.0-alpha.20 contain a fix for the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-27773</guid>
    </item>
  </channel>
</rss>
