The Saml Project maintains an authentication and identity-federation library that, despite limited disclosure volume, serves foundational infrastructure across numerous enterprise and cloud platforms where single sign-on and federated identity are critical. Its observed weakness classes center on resource exhaustion, authentication logic gaps, input validation failures, and cross-site scripting, reflecting the protocol-parsing and state-management complexity inherent to SAML implementations. Current exposure counts and live vulnerability details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Saml Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-41912CRITICAL The crewjam/saml go library prior to version 0.4.9 is vulnerable to an authentication bypass when processing SAML responses containing multiple Assertion elements. This issue has b | Nov 28, 2022 | 9.8 | 33 | NO | NO |
CVE-2020-27846CRITICAL A signature verification vulnerability exists in crewjam/saml. This flaw allows an attacker to bypass SAML Authentication. The highest threat from this vulnerability is to confiden | Dec 21, 2020 | 9.8 | 32 | NO | NO |
CVE-2023-28119HIGH The crewjam/saml go library contains a partial implementation of the SAML standard in golang. Prior to version 0.4.13, the package's use of `flate.NewReader` does not limit the siz | Mar 22, 2023 | 7.5 | 19 | NO | NO |
CVE-2023-45683MEDIUM github.com/crewjam/saml is a saml library for the go language. In affected versions the package does not validate the ACS Location URI according to the SAML binding being parsed. I | Oct 16, 2023 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Saml Project.
Media articles that mention a CVE ID that affects a product developed by Saml Project — matched by CVE ID, not by vendor name.