Pysaml2 is a foundational SAML 2.0 authentication library embedded across a wide range of identity and access management implementations, single sign-on platforms, and enterprise applications, despite its narrow product footprint. Vulnerabilities affecting the vendor skew toward serious outcomes, concentrating in cryptographic signature verification, XML external-entity handling, authentication logic, and random-number generation—all fundamental to SAML protocol integrity and the security of downstream systems that depend on correct identity assertion. Defenders should treat this library as a critical supply-chain component and prioritize patching within any applications or platforms that integrate it; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pysaml2 Project over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-1000433HIGH pysaml2 version 4.4.0 and older accept any password when run with python optimizations enabled. This allows attackers to log in as any user without knowing their password. | Jan 2, 2018 | 8.1 | 27 | NO | NO |
CVE-2016-10149HIGH XML External Entity (XXE) vulnerability in PySAML2 4.4.0 and earlier allows remote attackers to read arbitrary files via a crafted SAML XML request or response. | Mar 24, 2017 | 7.5 | 27 | NO | NO |
CVE-2020-5390HIGH PySAML2 before 5.0.0 does not check that the signature in a SAML document is enveloped and thus signature wrapping is effective, i.e., it is affected by XML Signature Wrapping (XSW | Jan 13, 2020 | 7.5 | 24 | NO | NO |
CVE-2016-10127CRITICAL PySAML2 allows remote attackers to conduct XML external entity (XXE) attacks via a crafted SAML XML request or response. | Mar 3, 2017 | 9.0 | 23 | NO | NO |
CVE-2021-21239MEDIUM PySAML2 is a pure python implementation of SAML Version 2 Standard. PySAML2 before 6.5.0 has an improper verification of cryptographic signature vulnerability. Users of pysaml2 tha | Jan 21, 2021 | 6.5 | 22 | NO | NO |
CVE-2021-21238MEDIUM PySAML2 is a pure python implementation of SAML Version 2 Standard. PySAML2 before 6.5.0 has an improper verification of cryptographic signature vulnerability. All users of pysaml2 | Jan 21, 2021 | 6.5 | 21 | NO | NO |
CVE-2017-1000246MEDIUM Python package pysaml2 version 4.4.0 and earlier reuses the initialization vector across encryptions in the IDP server, resulting in weak encryption of data. | Nov 17, 2017 | 5.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pysaml2 Project.
Media articles that mention a CVE ID that affects a product developed by Pysaml2 Project — matched by CVE ID, not by vendor name.