Shibboleth maintains a focused but widely integrated suite of single sign-on and identity-federation components, including its Service Provider, Identity Provider, and OpenSAML libraries, that anchor authentication and authorization across research institutions, enterprises, and federated identity ecosystems. The vendor's vulnerability exposure recurs through cryptographic signature verification flaws, information disclosure, server-side request forgery, and authentication weaknesses inherent to SAML processing and XML handling, compounded by the sensitive role these components play in controlling access to protected resources. Public exploit code has shown notable availability for this vendor's flaws, making timely patching essential for defenders operating federated identity infrastructure; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Shibboleth over time
Signals from CVEs in this vendor scope (20 CVEs).
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-24129HIGH The OIDC OP plugin before 3.0.4 for Shibboleth Identity Provider allows server-side request forgery (SSRF) due to insufficient restriction of the request_uri parameter. This allows | Feb 4, 2022 | 8.2 | 42 | NO | YES |
CVE-2023-36661HIGH Shibboleth XMLTooling before 3.2.4, as used in OpenSAML and Shibboleth Service Provider, allows SSRF via a crafted KeyInfo element. (This is fixed in, for example, Shibboleth Servi | Jun 25, 2023 | 7.5 | 35 | NO | YES |
CVE-2025-9943CRITICAL An SQL injection vulnerability has been identified in the "ID" attribute of the SAML response when the replay cache of the Shibboleth Service Provider (SP) is configured to use an | Sep 10, 2025 | 9.1 | 27 | NO | NO |
CVE-2017-16853HIGH The DynamicMetadataProvider class in saml/saml2/metadata/impl/DynamicMetadataProvider.cpp in OpenSAML-C in OpenSAML before 2.6.1 fails to properly configure itself with the Metadat | Nov 16, 2017 | 8.1 | 27 | NO | NO |
CVE-2010-2450HIGH The keygen.sh script in Shibboleth SP 2.0 (located in /usr/local/etc/shibboleth by default) uses OpenSSL to create a DES private key which is placed in sp-key.pm. It relies on the | Nov 7, 2019 | 7.5 | 25 | NO | NO |
CVE-2017-16852HIGH shibsp/metadata/DynamicMetadataProvider.cpp in the Dynamic MetadataProvider plugin in Shibboleth Service Provider before 2.6.1 fails to properly configure itself with the MetadataF | Nov 16, 2017 | 8.1 | 25 | NO | NO |
CVE-2023-22947HIGH Insecure folder permissions in the Windows installation path of Shibboleth Service Provider (SP) before 3.4.1 allow an unprivileged local attacker to escalate privileges to SYSTEM | Jan 11, 2023 | 7.3 | 24 | NO | NO |
CVE-2021-31826HIGH Shibboleth Service Provider 3.x before 3.2.2 is prone to a NULL pointer dereference flaw involving the session recovery feature. The flaw is exploitable (for a daemon crash) on sys | Apr 27, 2021 | 7.5 | 24 | NO | NO |
CVE-2020-27978HIGH Shibboleth Identify Provider 3.x before 3.4.6 has a denial of service flaw. A remote unauthenticated attacker can cause a login flow to trigger Java heap exhaustion due to the crea | Oct 28, 2020 | 7.5 | 24 | NO | NO |
CVE-2019-19191HIGH Shibboleth Service Provider (SP) 3.x before 3.1.0 shipped a spec file that calls chown on files in a directory controlled by the service user (the shibd account) after installation | Nov 21, 2019 | 7.8 | 23 | NO | NO |
Signals from CVEs in this vendor scope (20 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Shibboleth.
Media articles that mention a CVE ID that affects a product developed by Shibboleth — matched by CVE ID, not by vendor name.