Node Saml Project maintains a focused SAML authentication library for Node.js that, despite limited scope, addresses a critical authentication pathway in web applications and integrations. The durable signal centers on the library's cryptographic signature verification and session-management responsibilities, with observed weaknesses clustering around improper signature validation and insufficient session expiration—both of which are structurally significant in authentication contexts. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Node Saml Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-39300HIGH node SAML is a SAML 2.0 library based on the SAML implementation of passport-saml. A remote attacker may be able to bypass SAML authentication on a website using passport-saml. A s | Oct 13, 2022 | 8.1 | 26 | NO | NO |
CVE-2023-40178MEDIUM Node-SAML is a SAML library not dependent on any frameworks that runs in Node. The lack of checking of current timestamp allows a LogoutRequest XML to be reused multiple times even | Aug 23, 2023 | 5.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Node Saml Project.
Media articles that mention a CVE ID that affects a product developed by Node Saml Project — matched by CVE ID, not by vendor name.