github.com/russellhaering/gosaml2
Pure Go implementation of SAML 2.0
Activity
- Latest release
- 1mo ago
- Total releases
- 15
- Cadence
- ~4 months
- Last 12 months
- 2
Reach
- Stars
- 366
Details
- First release
- Mar 06, 2018
| Version | Released | |
|---|---|---|
v0.12.0
minor
|
v0.12.0
minor
Dependencies (5)
|
|
v0.11.0
minor
|
v0.11.0
minor
Dependencies (5)
|
|
v0.10.0
minor
2 CVEs
GO-2026-4764
GHSA-pcgw-qcv5-h8ch
Mar 27, 2026
Unsigned SAML LogoutRequest Acceptance in gosaml2 in github.com/russellhaering/gosaml2 Unsigned SAML LogoutRequest Acceptance in gosaml2 in github.com/russellhaering/gosaml2 Fixed in
0.11.0
Updated Mar 30, 2026 · Source: OSV.dev
GO-2026-4760
GHSA-hwqm-qvj9-4jr2
Mar 27, 2026
CBC Padding Panic — Unauthenticated Process Crash in github.com/russellhaering/gosaml2 CBC Padding Panic — Unauthenticated Process Crash in github.com/russellhaering/gosaml2 Fixed in
0.11.0
Updated Mar 30, 2026 · Source: OSV.dev |
v0.10.0
minor
Dependencies (5)
|
|
v0.9.1
patch
2 CVEs
GO-2026-4764
GHSA-pcgw-qcv5-h8ch
Mar 27, 2026
Unsigned SAML LogoutRequest Acceptance in gosaml2 in github.com/russellhaering/gosaml2 Unsigned SAML LogoutRequest Acceptance in gosaml2 in github.com/russellhaering/gosaml2 Fixed in
0.11.0
Updated Mar 30, 2026 · Source: OSV.dev
GO-2026-4760
GHSA-hwqm-qvj9-4jr2
Mar 27, 2026
CBC Padding Panic — Unauthenticated Process Crash in github.com/russellhaering/gosaml2 CBC Padding Panic — Unauthenticated Process Crash in github.com/russellhaering/gosaml2 Fixed in
0.11.0
Updated Mar 30, 2026 · Source: OSV.dev |
v0.9.1
patch
Dependencies (5)
|
|
v0.9.0
minor
2 CVEs
GO-2026-4764
GHSA-pcgw-qcv5-h8ch
Mar 27, 2026
Unsigned SAML LogoutRequest Acceptance in gosaml2 in github.com/russellhaering/gosaml2 Unsigned SAML LogoutRequest Acceptance in gosaml2 in github.com/russellhaering/gosaml2 Fixed in
0.11.0
Updated Mar 30, 2026 · Source: OSV.dev
GO-2026-4760
GHSA-hwqm-qvj9-4jr2
Mar 27, 2026
CBC Padding Panic — Unauthenticated Process Crash in github.com/russellhaering/gosaml2 CBC Padding Panic — Unauthenticated Process Crash in github.com/russellhaering/gosaml2 Fixed in
0.11.0
Updated Mar 30, 2026 · Source: OSV.dev |
v0.9.0
minor
Dependencies (5)
|
|
v0.8.1
patch
3 CVEs
GO-2026-4764
GHSA-pcgw-qcv5-h8ch
Mar 27, 2026
Unsigned SAML LogoutRequest Acceptance in gosaml2 in github.com/russellhaering/gosaml2 Unsigned SAML LogoutRequest Acceptance in gosaml2 in github.com/russellhaering/gosaml2 Fixed in
0.11.0
Updated Mar 30, 2026 · Source: OSV.dev
GO-2026-4760
GHSA-hwqm-qvj9-4jr2
Mar 27, 2026
CBC Padding Panic — Unauthenticated Process Crash in github.com/russellhaering/gosaml2 CBC Padding Panic — Unauthenticated Process Crash in github.com/russellhaering/gosaml2 Fixed in
0.11.0
Updated Mar 30, 2026 · Source: OSV.dev
CVE-2023-26483
GO-2023-1602
GHSA-6gc3-crp7-25w5
Mar 03, 2023
Denial of service via deflate decompression bomb in github.com/russellhaering/gosaml2 A bug in SAML authentication library can result in Denial of Service attacks. Attackers can craft a "deflate"-compressed request which will consume significantly more memory during processing than the size of the original request. This may eventually lead to memory exhaustion and the process being killed. Fixed in
0.9.0
References Updated May 20, 2024 · Source: OSV.dev |
v0.8.1
patch
Dependencies (5)
|
|
v0.8.0
minor
3 CVEs
GO-2026-4764
GHSA-pcgw-qcv5-h8ch
Mar 27, 2026
Unsigned SAML LogoutRequest Acceptance in gosaml2 in github.com/russellhaering/gosaml2 Unsigned SAML LogoutRequest Acceptance in gosaml2 in github.com/russellhaering/gosaml2 Fixed in
0.11.0
Updated Mar 30, 2026 · Source: OSV.dev
GO-2026-4760
GHSA-hwqm-qvj9-4jr2
Mar 27, 2026
CBC Padding Panic — Unauthenticated Process Crash in github.com/russellhaering/gosaml2 CBC Padding Panic — Unauthenticated Process Crash in github.com/russellhaering/gosaml2 Fixed in
0.11.0
Updated Mar 30, 2026 · Source: OSV.dev
CVE-2023-26483
GO-2023-1602
GHSA-6gc3-crp7-25w5
Mar 03, 2023
Denial of service via deflate decompression bomb in github.com/russellhaering/gosaml2 A bug in SAML authentication library can result in Denial of Service attacks. Attackers can craft a "deflate"-compressed request which will consume significantly more memory during processing than the size of the original request. This may eventually lead to memory exhaustion and the process being killed. Fixed in
0.9.0
References Updated May 20, 2024 · Source: OSV.dev |
v0.8.0
minor
Dependencies (5)
|
|
v0.7.0
minor
3 CVEs
GO-2026-4764
GHSA-pcgw-qcv5-h8ch
Mar 27, 2026
Unsigned SAML LogoutRequest Acceptance in gosaml2 in github.com/russellhaering/gosaml2 Unsigned SAML LogoutRequest Acceptance in gosaml2 in github.com/russellhaering/gosaml2 Fixed in
0.11.0
Updated Mar 30, 2026 · Source: OSV.dev
GO-2026-4760
GHSA-hwqm-qvj9-4jr2
Mar 27, 2026
CBC Padding Panic — Unauthenticated Process Crash in github.com/russellhaering/gosaml2 CBC Padding Panic — Unauthenticated Process Crash in github.com/russellhaering/gosaml2 Fixed in
0.11.0
Updated Mar 30, 2026 · Source: OSV.dev
CVE-2023-26483
GO-2023-1602
GHSA-6gc3-crp7-25w5
Mar 03, 2023
Denial of service via deflate decompression bomb in github.com/russellhaering/gosaml2 A bug in SAML authentication library can result in Denial of Service attacks. Attackers can craft a "deflate"-compressed request which will consume significantly more memory during processing than the size of the original request. This may eventually lead to memory exhaustion and the process being killed. Fixed in
0.9.0
References Updated May 20, 2024 · Source: OSV.dev |
v0.7.0
minor
Dependencies (5)
|
|
v0.6.0
minor
4 CVEs
GO-2026-4764
GHSA-pcgw-qcv5-h8ch
Mar 27, 2026
Unsigned SAML LogoutRequest Acceptance in gosaml2 in github.com/russellhaering/gosaml2 Unsigned SAML LogoutRequest Acceptance in gosaml2 in github.com/russellhaering/gosaml2 Fixed in
0.11.0
Updated Mar 30, 2026 · Source: OSV.dev
GO-2026-4760
GHSA-hwqm-qvj9-4jr2
Mar 27, 2026
CBC Padding Panic — Unauthenticated Process Crash in github.com/russellhaering/gosaml2 CBC Padding Panic — Unauthenticated Process Crash in github.com/russellhaering/gosaml2 Fixed in
0.11.0
Updated Mar 30, 2026 · Source: OSV.dev
CVE-2023-26483
GO-2023-1602
GHSA-6gc3-crp7-25w5
Mar 03, 2023
Denial of service via deflate decompression bomb in github.com/russellhaering/gosaml2 A bug in SAML authentication library can result in Denial of Service attacks. Attackers can craft a "deflate"-compressed request which will consume significantly more memory during processing than the size of the original request. This may eventually lead to memory exhaustion and the process being killed. Fixed in
0.9.0
References Updated May 20, 2024 · Source: OSV.dev
CVE-2020-7711
GHSA-prjq-f4q3-fvfr
CVE-2020-7731
GHSA-gq5r-cc4w-g8xf
GHSA-mqqv-chpx-vq25
GO-2020-0046
SNYK-GOLANG-GITHUBCOMRUSSELLHAERINGGOSAML2-608302
Nov 15, 2022
github.com/russellhaering/gosaml2 is vulnerable to NULL Pointer Dereference
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactIn versions prior to v0.7.0 it was possible for an attacker to supply an invalid assertion which would trigger a panic due to a nil-pointer dereference. PatchesThe issue was patched in v0.7.0, released on March 2, 2022. WorkaroundsCallers to ReferencesSee issue #59 for details. Fixed in
0.7.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
v0.6.0
minor
Dependencies (5)
|
|
v0.5.0
minor
5 CVEs
GO-2026-4764
GHSA-pcgw-qcv5-h8ch
Mar 27, 2026
Unsigned SAML LogoutRequest Acceptance in gosaml2 in github.com/russellhaering/gosaml2 Unsigned SAML LogoutRequest Acceptance in gosaml2 in github.com/russellhaering/gosaml2 Fixed in
0.11.0
Updated Mar 30, 2026 · Source: OSV.dev
GO-2026-4760
GHSA-hwqm-qvj9-4jr2
Mar 27, 2026
CBC Padding Panic — Unauthenticated Process Crash in github.com/russellhaering/gosaml2 CBC Padding Panic — Unauthenticated Process Crash in github.com/russellhaering/gosaml2 Fixed in
0.11.0
Updated Mar 30, 2026 · Source: OSV.dev
CVE-2023-26483
GO-2023-1602
GHSA-6gc3-crp7-25w5
Mar 03, 2023
Denial of service via deflate decompression bomb in github.com/russellhaering/gosaml2 A bug in SAML authentication library can result in Denial of Service attacks. Attackers can craft a "deflate"-compressed request which will consume significantly more memory during processing than the size of the original request. This may eventually lead to memory exhaustion and the process being killed. Fixed in
0.9.0
References Updated May 20, 2024 · Source: OSV.dev
CVE-2020-7711
GHSA-prjq-f4q3-fvfr
CVE-2020-7731
GHSA-gq5r-cc4w-g8xf
GHSA-mqqv-chpx-vq25
GO-2020-0046
SNYK-GOLANG-GITHUBCOMRUSSELLHAERINGGOSAML2-608302
Nov 15, 2022
github.com/russellhaering/gosaml2 is vulnerable to NULL Pointer Dereference
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactIn versions prior to v0.7.0 it was possible for an attacker to supply an invalid assertion which would trigger a panic due to a nil-pointer dereference. PatchesThe issue was patched in v0.7.0, released on March 2, 2022. WorkaroundsCallers to ReferencesSee issue #59 for details. Fixed in
0.7.0
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2020-29509
GHSA-xhqq-x44f-9fgg
BIT-golang-2020-29509
GO-2021-0060
Feb 11, 2022
Authentication Bypass in github.com/russellhaering/gosaml2
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactGiven a valid SAML Response, it may be possible for an attacker to mutate the XML document in such a way that gosaml2 will trust a different portion of the document than was signed. Depending on the implementation of the Service Provider this enables a variety of attacks, including users accessing accounts other than the one to which they authenticated in the Identity Provider, or full authentication bypass. PatchesService Providers utilizing gosaml2 should upgrade to v0.6.0 or greater. Fixed in
0.6.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
v0.5.0
minor
Dependencies (4)
|
|
v0.4.0
minor
6 CVEs
GO-2026-4764
GHSA-pcgw-qcv5-h8ch
Mar 27, 2026
Unsigned SAML LogoutRequest Acceptance in gosaml2 in github.com/russellhaering/gosaml2 Unsigned SAML LogoutRequest Acceptance in gosaml2 in github.com/russellhaering/gosaml2 Fixed in
0.11.0
Updated Mar 30, 2026 · Source: OSV.dev
GO-2026-4760
GHSA-hwqm-qvj9-4jr2
Mar 27, 2026
CBC Padding Panic — Unauthenticated Process Crash in github.com/russellhaering/gosaml2 CBC Padding Panic — Unauthenticated Process Crash in github.com/russellhaering/gosaml2 Fixed in
0.11.0
Updated Mar 30, 2026 · Source: OSV.dev
CVE-2023-26483
GO-2023-1602
GHSA-6gc3-crp7-25w5
Mar 03, 2023
Denial of service via deflate decompression bomb in github.com/russellhaering/gosaml2 A bug in SAML authentication library can result in Denial of Service attacks. Attackers can craft a "deflate"-compressed request which will consume significantly more memory during processing than the size of the original request. This may eventually lead to memory exhaustion and the process being killed. Fixed in
0.9.0
References Updated May 20, 2024 · Source: OSV.dev
CVE-2020-7711
GHSA-prjq-f4q3-fvfr
CVE-2020-7731
GHSA-gq5r-cc4w-g8xf
GHSA-mqqv-chpx-vq25
GO-2020-0046
SNYK-GOLANG-GITHUBCOMRUSSELLHAERINGGOSAML2-608302
Nov 15, 2022
github.com/russellhaering/gosaml2 is vulnerable to NULL Pointer Dereference
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactIn versions prior to v0.7.0 it was possible for an attacker to supply an invalid assertion which would trigger a panic due to a nil-pointer dereference. PatchesThe issue was patched in v0.7.0, released on March 2, 2022. WorkaroundsCallers to ReferencesSee issue #59 for details. Fixed in
0.7.0
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2020-29509
GHSA-xhqq-x44f-9fgg
BIT-golang-2020-29509
GO-2021-0060
Feb 11, 2022
Authentication Bypass in github.com/russellhaering/gosaml2
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactGiven a valid SAML Response, it may be possible for an attacker to mutate the XML document in such a way that gosaml2 will trust a different portion of the document than was signed. Depending on the implementation of the Service Provider this enables a variety of attacks, including users accessing accounts other than the one to which they authenticated in the Identity Provider, or full authentication bypass. PatchesService Providers utilizing gosaml2 should upgrade to v0.6.0 or greater. Fixed in
0.6.0
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-5684-g483-2249
May 24, 2021
Signature Validation Bypass
Critical
ImpactGiven a valid SAML Response, an attacker can potentially modify the document, bypassing signature validation in order to pass off the altered document as a signed one. This enables a variety of attacks, including users accessing accounts other than the one to which they authenticated in the identity provider, or full authentication bypass if an external attacker can obtain an expired, signed SAML Response. PatchesA patch is available, users of gosaml2 should upgrade to v0.5.0 or higher. ReferencesSee the underlying advisory on goxmldsig for more details. Fixed in
0.5.0
References Updated Oct 05, 2021 · Source: OSV.dev |
v0.4.0
minor
Dependencies (4)
|
|
v0.3.1
patch
6 CVEs
GO-2026-4764
GHSA-pcgw-qcv5-h8ch
Mar 27, 2026
Unsigned SAML LogoutRequest Acceptance in gosaml2 in github.com/russellhaering/gosaml2 Unsigned SAML LogoutRequest Acceptance in gosaml2 in github.com/russellhaering/gosaml2 Fixed in
0.11.0
Updated Mar 30, 2026 · Source: OSV.dev
GO-2026-4760
GHSA-hwqm-qvj9-4jr2
Mar 27, 2026
CBC Padding Panic — Unauthenticated Process Crash in github.com/russellhaering/gosaml2 CBC Padding Panic — Unauthenticated Process Crash in github.com/russellhaering/gosaml2 Fixed in
0.11.0
Updated Mar 30, 2026 · Source: OSV.dev
CVE-2023-26483
GO-2023-1602
GHSA-6gc3-crp7-25w5
Mar 03, 2023
Denial of service via deflate decompression bomb in github.com/russellhaering/gosaml2 A bug in SAML authentication library can result in Denial of Service attacks. Attackers can craft a "deflate"-compressed request which will consume significantly more memory during processing than the size of the original request. This may eventually lead to memory exhaustion and the process being killed. Fixed in
0.9.0
References Updated May 20, 2024 · Source: OSV.dev
CVE-2020-7711
GHSA-prjq-f4q3-fvfr
CVE-2020-7731
GHSA-gq5r-cc4w-g8xf
GHSA-mqqv-chpx-vq25
GO-2020-0046
SNYK-GOLANG-GITHUBCOMRUSSELLHAERINGGOSAML2-608302
Nov 15, 2022
github.com/russellhaering/gosaml2 is vulnerable to NULL Pointer Dereference
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactIn versions prior to v0.7.0 it was possible for an attacker to supply an invalid assertion which would trigger a panic due to a nil-pointer dereference. PatchesThe issue was patched in v0.7.0, released on March 2, 2022. WorkaroundsCallers to ReferencesSee issue #59 for details. Fixed in
0.7.0
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2020-29509
GHSA-xhqq-x44f-9fgg
BIT-golang-2020-29509
GO-2021-0060
Feb 11, 2022
Authentication Bypass in github.com/russellhaering/gosaml2
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactGiven a valid SAML Response, it may be possible for an attacker to mutate the XML document in such a way that gosaml2 will trust a different portion of the document than was signed. Depending on the implementation of the Service Provider this enables a variety of attacks, including users accessing accounts other than the one to which they authenticated in the Identity Provider, or full authentication bypass. PatchesService Providers utilizing gosaml2 should upgrade to v0.6.0 or greater. Fixed in
0.6.0
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-5684-g483-2249
May 24, 2021
Signature Validation Bypass
Critical
ImpactGiven a valid SAML Response, an attacker can potentially modify the document, bypassing signature validation in order to pass off the altered document as a signed one. This enables a variety of attacks, including users accessing accounts other than the one to which they authenticated in the identity provider, or full authentication bypass if an external attacker can obtain an expired, signed SAML Response. PatchesA patch is available, users of gosaml2 should upgrade to v0.5.0 or higher. ReferencesSee the underlying advisory on goxmldsig for more details. Fixed in
0.5.0
References Updated Oct 05, 2021 · Source: OSV.dev |
v0.3.1
patch
|
|
v0.3.0
minor
6 CVEs
GO-2026-4764
GHSA-pcgw-qcv5-h8ch
Mar 27, 2026
Unsigned SAML LogoutRequest Acceptance in gosaml2 in github.com/russellhaering/gosaml2 Unsigned SAML LogoutRequest Acceptance in gosaml2 in github.com/russellhaering/gosaml2 Fixed in
0.11.0
Updated Mar 30, 2026 · Source: OSV.dev
GO-2026-4760
GHSA-hwqm-qvj9-4jr2
Mar 27, 2026
CBC Padding Panic — Unauthenticated Process Crash in github.com/russellhaering/gosaml2 CBC Padding Panic — Unauthenticated Process Crash in github.com/russellhaering/gosaml2 Fixed in
0.11.0
Updated Mar 30, 2026 · Source: OSV.dev
CVE-2023-26483
GO-2023-1602
GHSA-6gc3-crp7-25w5
Mar 03, 2023
Denial of service via deflate decompression bomb in github.com/russellhaering/gosaml2 A bug in SAML authentication library can result in Denial of Service attacks. Attackers can craft a "deflate"-compressed request which will consume significantly more memory during processing than the size of the original request. This may eventually lead to memory exhaustion and the process being killed. Fixed in
0.9.0
References Updated May 20, 2024 · Source: OSV.dev
CVE-2020-7711
GHSA-prjq-f4q3-fvfr
CVE-2020-7731
GHSA-gq5r-cc4w-g8xf
GHSA-mqqv-chpx-vq25
GO-2020-0046
SNYK-GOLANG-GITHUBCOMRUSSELLHAERINGGOSAML2-608302
Nov 15, 2022
github.com/russellhaering/gosaml2 is vulnerable to NULL Pointer Dereference
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactIn versions prior to v0.7.0 it was possible for an attacker to supply an invalid assertion which would trigger a panic due to a nil-pointer dereference. PatchesThe issue was patched in v0.7.0, released on March 2, 2022. WorkaroundsCallers to ReferencesSee issue #59 for details. Fixed in
0.7.0
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2020-29509
GHSA-xhqq-x44f-9fgg
BIT-golang-2020-29509
GO-2021-0060
Feb 11, 2022
Authentication Bypass in github.com/russellhaering/gosaml2
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactGiven a valid SAML Response, it may be possible for an attacker to mutate the XML document in such a way that gosaml2 will trust a different portion of the document than was signed. Depending on the implementation of the Service Provider this enables a variety of attacks, including users accessing accounts other than the one to which they authenticated in the Identity Provider, or full authentication bypass. PatchesService Providers utilizing gosaml2 should upgrade to v0.6.0 or greater. Fixed in
0.6.0
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-5684-g483-2249
May 24, 2021
Signature Validation Bypass
Critical
ImpactGiven a valid SAML Response, an attacker can potentially modify the document, bypassing signature validation in order to pass off the altered document as a signed one. This enables a variety of attacks, including users accessing accounts other than the one to which they authenticated in the identity provider, or full authentication bypass if an external attacker can obtain an expired, signed SAML Response. PatchesA patch is available, users of gosaml2 should upgrade to v0.5.0 or higher. ReferencesSee the underlying advisory on goxmldsig for more details. Fixed in
0.5.0
References Updated Oct 05, 2021 · Source: OSV.dev |
v0.3.0
minor
|
|
v0.2.0
minor
6 CVEs
GO-2026-4764
GHSA-pcgw-qcv5-h8ch
Mar 27, 2026
Unsigned SAML LogoutRequest Acceptance in gosaml2 in github.com/russellhaering/gosaml2 Unsigned SAML LogoutRequest Acceptance in gosaml2 in github.com/russellhaering/gosaml2 Fixed in
0.11.0
Updated Mar 30, 2026 · Source: OSV.dev
GO-2026-4760
GHSA-hwqm-qvj9-4jr2
Mar 27, 2026
CBC Padding Panic — Unauthenticated Process Crash in github.com/russellhaering/gosaml2 CBC Padding Panic — Unauthenticated Process Crash in github.com/russellhaering/gosaml2 Fixed in
0.11.0
Updated Mar 30, 2026 · Source: OSV.dev
CVE-2023-26483
GO-2023-1602
GHSA-6gc3-crp7-25w5
Mar 03, 2023
Denial of service via deflate decompression bomb in github.com/russellhaering/gosaml2 A bug in SAML authentication library can result in Denial of Service attacks. Attackers can craft a "deflate"-compressed request which will consume significantly more memory during processing than the size of the original request. This may eventually lead to memory exhaustion and the process being killed. Fixed in
0.9.0
References Updated May 20, 2024 · Source: OSV.dev
CVE-2020-7711
GHSA-prjq-f4q3-fvfr
CVE-2020-7731
GHSA-gq5r-cc4w-g8xf
GHSA-mqqv-chpx-vq25
GO-2020-0046
SNYK-GOLANG-GITHUBCOMRUSSELLHAERINGGOSAML2-608302
Nov 15, 2022
github.com/russellhaering/gosaml2 is vulnerable to NULL Pointer Dereference
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactIn versions prior to v0.7.0 it was possible for an attacker to supply an invalid assertion which would trigger a panic due to a nil-pointer dereference. PatchesThe issue was patched in v0.7.0, released on March 2, 2022. WorkaroundsCallers to ReferencesSee issue #59 for details. Fixed in
0.7.0
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2020-29509
GHSA-xhqq-x44f-9fgg
BIT-golang-2020-29509
GO-2021-0060
Feb 11, 2022
Authentication Bypass in github.com/russellhaering/gosaml2
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactGiven a valid SAML Response, it may be possible for an attacker to mutate the XML document in such a way that gosaml2 will trust a different portion of the document than was signed. Depending on the implementation of the Service Provider this enables a variety of attacks, including users accessing accounts other than the one to which they authenticated in the Identity Provider, or full authentication bypass. PatchesService Providers utilizing gosaml2 should upgrade to v0.6.0 or greater. Fixed in
0.6.0
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-5684-g483-2249
May 24, 2021
Signature Validation Bypass
Critical
ImpactGiven a valid SAML Response, an attacker can potentially modify the document, bypassing signature validation in order to pass off the altered document as a signed one. This enables a variety of attacks, including users accessing accounts other than the one to which they authenticated in the identity provider, or full authentication bypass if an external attacker can obtain an expired, signed SAML Response. PatchesA patch is available, users of gosaml2 should upgrade to v0.5.0 or higher. ReferencesSee the underlying advisory on goxmldsig for more details. Fixed in
0.5.0
References Updated Oct 05, 2021 · Source: OSV.dev |
v0.2.0
minor
|
|
v0.1.0
initial
6 CVEs
GO-2026-4764
GHSA-pcgw-qcv5-h8ch
Mar 27, 2026
Unsigned SAML LogoutRequest Acceptance in gosaml2 in github.com/russellhaering/gosaml2 Unsigned SAML LogoutRequest Acceptance in gosaml2 in github.com/russellhaering/gosaml2 Fixed in
0.11.0
Updated Mar 30, 2026 · Source: OSV.dev
GO-2026-4760
GHSA-hwqm-qvj9-4jr2
Mar 27, 2026
CBC Padding Panic — Unauthenticated Process Crash in github.com/russellhaering/gosaml2 CBC Padding Panic — Unauthenticated Process Crash in github.com/russellhaering/gosaml2 Fixed in
0.11.0
Updated Mar 30, 2026 · Source: OSV.dev
CVE-2023-26483
GO-2023-1602
GHSA-6gc3-crp7-25w5
Mar 03, 2023
Denial of service via deflate decompression bomb in github.com/russellhaering/gosaml2 A bug in SAML authentication library can result in Denial of Service attacks. Attackers can craft a "deflate"-compressed request which will consume significantly more memory during processing than the size of the original request. This may eventually lead to memory exhaustion and the process being killed. Fixed in
0.9.0
References Updated May 20, 2024 · Source: OSV.dev
CVE-2020-7711
GHSA-prjq-f4q3-fvfr
CVE-2020-7731
GHSA-gq5r-cc4w-g8xf
GHSA-mqqv-chpx-vq25
GO-2020-0046
SNYK-GOLANG-GITHUBCOMRUSSELLHAERINGGOSAML2-608302
Nov 15, 2022
github.com/russellhaering/gosaml2 is vulnerable to NULL Pointer Dereference
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactIn versions prior to v0.7.0 it was possible for an attacker to supply an invalid assertion which would trigger a panic due to a nil-pointer dereference. PatchesThe issue was patched in v0.7.0, released on March 2, 2022. WorkaroundsCallers to ReferencesSee issue #59 for details. Fixed in
0.7.0
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2020-29509
GHSA-xhqq-x44f-9fgg
BIT-golang-2020-29509
GO-2021-0060
Feb 11, 2022
Authentication Bypass in github.com/russellhaering/gosaml2
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactGiven a valid SAML Response, it may be possible for an attacker to mutate the XML document in such a way that gosaml2 will trust a different portion of the document than was signed. Depending on the implementation of the Service Provider this enables a variety of attacks, including users accessing accounts other than the one to which they authenticated in the Identity Provider, or full authentication bypass. PatchesService Providers utilizing gosaml2 should upgrade to v0.6.0 or greater. Fixed in
0.6.0
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-5684-g483-2249
May 24, 2021
Signature Validation Bypass
Critical
ImpactGiven a valid SAML Response, an attacker can potentially modify the document, bypassing signature validation in order to pass off the altered document as a signed one. This enables a variety of attacks, including users accessing accounts other than the one to which they authenticated in the identity provider, or full authentication bypass if an external attacker can obtain an expired, signed SAML Response. PatchesA patch is available, users of gosaml2 should upgrade to v0.5.0 or higher. ReferencesSee the underlying advisory on goxmldsig for more details. Fixed in
0.5.0
References Updated Oct 05, 2021 · Source: OSV.dev |
v0.1.0
initial
|