<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 04:13:57 +0000</lastBuildDate>
    <item>
      <title>CVE-2019-3465</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2019-3465</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rob Richards XmlSecLibs&lt;/p&gt;
&lt;p&gt;Rob Richards XmlSecLibs, all versions prior to v3.0.3, as used for example by SimpleSAMLphp, performed incorrect validation of cryptographic signatures in XML messages, allowing an authenticated attacker to impersonate others or elevate privileges by creating a crafted XML message.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rob Richards XmlSecLibs&lt;/p&gt;
&lt;p&gt;Rob Richards XmlSecLibs, all versions prior to v3.0.3, as used for example by SimpleSAMLphp, performed incorrect validation of cryptographic signatures in XML messages, allowing an authenticated attacker to impersonate others or elevate privileges by creating a crafted XML message.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2019-3465</guid>
    </item>
    <item>
      <title>USN-8770-1 — simplesamlphp vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/usn-8770-1</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: simplesamlphp, Ubuntu:Pro:18.04:LTS: simplesamlphp, Ubuntu:Pro:20.04:LTS: simplesamlphp, Ubuntu:Pro:22.04:LTS: simplesamlphp, Ubuntu:24.04:LTS: simplesamlphp&lt;/p&gt;
&lt;p&gt;It was discovered that SimpleSAMLphp incorrectly validated cryptographic
signatures in XML messages. An authenticated attacker could possibly use
this issue to impersonate users or gain elevated privileges. This issue
only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2019-3465)&lt;/p&gt;
&lt;p&gt;It was discovered that SimpleSAMLphp incorrectly handled external entities
when parsing untrusted XML documents. A remote attacker could possibly use
this issue to obtain sensitive information. This issue did not affect
Ubuntu 24.04 LTS. (CVE-2024-52596)&lt;/p&gt;
&lt;p&gt;It was discovered that SimpleSAMLphp incorrectly verified signatures in
SAML messages using the HTTP-Redirect binding. A remote attacker could
possibly use this issue to bypass authentication and impersonate users.
(CVE-2025-27773)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: simplesamlphp, Ubuntu:Pro:18.04:LTS: simplesamlphp, Ubuntu:Pro:20.04:LTS: simplesamlphp, Ubuntu:Pro:22.04:LTS: simplesamlphp, Ubuntu:24.04:LTS: simplesamlphp&lt;/p&gt;
&lt;p&gt;It was discovered that SimpleSAMLphp incorrectly validated cryptographic
signatures in XML messages. An authenticated attacker could possibly use
this issue to impersonate users or gain elevated privileges. This issue
only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2019-3465)&lt;/p&gt;
&lt;p&gt;It was discovered that SimpleSAMLphp incorrectly handled external entities
when parsing untrusted XML documents. A remote attacker could possibly use
this issue to obtain sensitive information. This issue did not affect
Ubuntu 24.04 LTS. (CVE-2024-52596)&lt;/p&gt;
&lt;p&gt;It was discovered that SimpleSAMLphp incorrectly verified signatures in
SAML messages using the HTTP-Redirect binding. A remote attacker could
possibly use this issue to bypass authentication and impersonate users.
(CVE-2025-27773)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/usn-8770-1</guid>
    </item>
  </channel>
</rss>
