Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2020-5390

24
FAUCET Score

CVE-2020-5390 describes an XML Signature Wrapping (XSW) vulnerability in PySAML2 versions prior to 5.0.0, affecting products like Canonical and Debian Linux distributions that utilize PySAML2. This flaw allows an attacker to manipulate SAML assertions by separating the signature from the signed data, leading to successful signature verification of incorrect information. With a CVSS score of 7.5 (HIGH), this vulnerability is remotely exploitable with low attack complexity, potentially leading to high integrity impacts without requiring user interaction. While no public exploits, Metasploit modules, or Nuclei templates are currently available, and there is minimal community discussion, organizations using affected PySAML2 versions should prioritize patching.

Impacted Technologies

VendorProductVersion(s)CPE
< 5.0.0CPE matchmatch criteria
cpe:2.3:a:pysaml2_project:pysaml2:*:*:*:*:*:*:*:*
16.04CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*
18.04CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
19.04CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:19.04:*:*:*:*:*:*:*
19.10CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:19.10:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.22%
Probability of exploitation in next 30 days
EPSS Percentile
65.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0122 is in the 45th percentile among its peer group of 51,551 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (5)

github_advisorypatch availablevia nvd_reference
View patch
pippatch availablevia ghsa
Product: pysaml2Fixed in: 5.0.0
redhatend of lifevia redhat_api
Product: Red Hat OpenStack Platform 13 (Queens)Fixed in: python-pysaml2
redhatend of lifevia redhat_api
Product: Red Hat OpenStack Platform 15 (Stein)Fixed in: python-pysaml2
redhatend of lifevia redhat_api
Product: Red Hat OpenStack Platform 16 (Train)Fixed in: python-pysaml2

Vendor Advisories (2)

pipGHSA-qf7v-8hj3-4xw7high

Improper Verification of Cryptographic Signature in PySAML2

May 6, 2020
redhatCVE-2020-5390Important

python-pysaml2: does not check that the signature in a SAML document is enveloped

Jan 13, 2020

References

github.com / IdentityPython/pysaml2/commit/5e9d5acbcd8ae45c4e736ac521fd2df5b1c62e25
PatchThird Party Advisory
github.com / IdentityPython/pysaml2/commit/f27c7e7a7010f83380566a219fd6a290a00f2b6e
PatchThird Party Advisory
github.com / IdentityPython/pysaml2/releases
Release NotesThird Party Advisory
github.com / IdentityPython/pysaml2/releases/tag/v5.0.0
Release NotesThird Party Advisory
lists.debian.org / debian-lts-announce/2020/02/msg00025.html
Mailing ListThird Party Advisory
pypi.org / project/pysaml2/5.0.0
ProductThird Party Advisory
usn.ubuntu.com / 4245-1
Third Party Advisory
debian.org / security/2020/dsa-4630
Third Party Advisory