timlegge Net::SAML2是timlegge个人开发者的一款实现SAML2协议的Perl库。 TIMLEGGE Net::SAML2 0.86之前版本存在加密问题漏洞,该漏洞源于new_from_xml读取断言身份时使用文档范围的XPath而非签名子树,可能导致SAML身份验证绕过,攻击者持有一个IdP签名的断言即可添加未签名的攻击者断言,从而以任意用户身份进行认证。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| TIMLEGGE | Net::SAML2 | < 0.86 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| TIMLEGGE | Net::SAML2 | 0 ~ 0.86 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-18108 | Net::SAML2 versions before 0.86 for Perl allow authentication bypass because _verify_encry | |
| CVE-2026-18089 | Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass by verifying res | |
| CVE-2026-9390 | XML::Sig versions before 0.71 for Perl allow XPath injection in ID lookup | |
| CVE-2026-9487 | XML::Sig versions before 0.71 for Perl allow signature wrapping via duplicate ID | |
| CVE-2026-18568 | XML::Sig versions from 0.29 before 0.72 for Perl allow signature verification bypass becau |
No comments yet