Samlify is a focused SAML library project with a narrow product footprint centered on its single namesake implementation, used in authentication and identity-federation workflows across web applications and services. Its durable vulnerability signal centers on XML-processing and cryptographic-validation weaknesses, specifically XML injection attacks and improper verification of digital signatures, which reflect the parsing and trust-boundary challenges inherent to SAML protocol implementations. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Samlify Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-46490HIGH samlify is a Node.js library for SAML single sign-on. Prior to version 2.13.0, samlify’s template substitution only escapes attribute contexts. Values inserted into element text (e | Jun 8, 2026 | 8.8 | 36 | NO | NO |
CVE-2025-47949HIGH samlify is a Node.js library for SAML single sign-on. A Signature Wrapping attack has been found in samlify prior to version 2.10.0, allowing an attacker to forge a SAML Response t | May 19, 2025 | 7.5 | 25 | NO | NO |
CVE-2017-1000452HIGH An XML Signature Wrapping vulnerability exists in Samlify 2.2.0 and earlier, and in predecessor Express-saml2 which could allow attackers to impersonate arbitrary users. | Jan 2, 2018 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Samlify Project.
Media articles that mention a CVE ID that affects a product developed by Samlify Project — matched by CVE ID, not by vendor name.