CVE-2024-52806

SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. When loading an (untrusted) XML document, for example the SAMLResponse, it's possible to induce an XXE. This vulnerability is fixed in 4.6.14 and 5.0.0-alpha.18.
Configurations

No configuration.

History

15 Apr 2026, 00:35

Type Values Removed Values Added
Summary
  • (es) La librería SAML2 SimpleSAMLphp es una librería PHP para funciones relacionadas con SAML2. Al cargar un documento XML (no confiable), por ejemplo, SAMLResponse, es posible inducir un XXE. Esta vulnerabilidad se solucionó en 4.6.14 y 5.0.0-alpha.18.

02 Dec 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-02 17:15

Updated : 2026-06-17 08:07


NVD link : CVE-2024-52806

Mitre link : CVE-2024-52806

CVE.ORG link : CVE-2024-52806


JSON object : View

Products Affected

No product.

CWE
CWE-611

Improper Restriction of XML External Entity Reference