The Xmltooling Project maintains a specialized XML processing library used in SAML and federated-identity implementations, a niche but security-critical role in enterprise authentication infrastructure. The durable signal centers on the library's parsing and validation role, with observed weakness classes reflecting improper handling of exceptional conditions during XML processing. Current vulnerability counts, exploitation activity, and severity breakdown are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xmltooling Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-9628HIGH The XMLTooling library all versions prior to V3.0.4, provided with the OpenSAML and Shibboleth Service Provider software, contains an XML parsing class. Invalid data in the XML dec | Apr 11, 2019 | 7.5 | 20 | NO | NO |
CVE-2015-0851MEDIUM XMLTooling-C before 1.5.5, as used in OpenSAML-C and Shibboleth Service Provider (SP), does not properly handle integer conversion exceptions, which allows remote attackers to caus | Aug 12, 2015 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xmltooling Project.
Media articles that mention a CVE ID that affects a product developed by Xmltooling Project — matched by CVE ID, not by vendor name.