samly
SAML Single-Sign-On Authentication for Plug/Phoenix Applications
Activity
- Latest release
- 2y ago
- Total releases
- 28
- Cadence
- ~9 days
- Last 12 months
- 0
Details
- License
- MIT
- First release
- Aug 29, 2017
| Version | Released | |
|---|---|---|
1.4.0
minor
2 CVEs
CVE-2026-53424
EEF-CVE-2026-53424
Aug 20, 2026
Missing one-time-use enforcement in Samly allows replay of SAML bearer assertions
Critical
Network
Low
None
None
SummaryAuthentication Bypass by Capture-replay vulnerability in dropbox samly allows an attacker to authenticate as the subject of a captured SAML assertion by resubmitting it.
This issue affects samly: from 0.3.0 onward. Affected versions
0.10.0
0.10.1
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
+ 15 more Show less
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0-rc.0
1.0.0-rc.1
1.1.0
1.2.0
1.3.0
1.4.0
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-53425
EEF-CVE-2026-53425
Aug 20, 2026
Missing InResponseTo validation in Samly allows acceptance of unsolicited SAML responses
Critical
Network
Low
None
SummaryInsufficient Verification of Data Authenticity vulnerability in dropbox samly allows an attacker to establish an authenticated session using a SAML response the service provider never requested.
This issue affects samly: from 0.3.0 onward. Affected versions
0.10.0
0.10.1
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
+ 15 more Show less
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0-rc.0
1.0.0-rc.1
1.1.0
1.2.0
1.3.0
1.4.0
Updated Sep 08, 2026 · Source: OSV.dev | ||
1.3.0
minor
3 CVEs
CVE-2026-53424
EEF-CVE-2026-53424
Aug 20, 2026
Missing one-time-use enforcement in Samly allows replay of SAML bearer assertions
Critical
Network
Low
None
None
SummaryAuthentication Bypass by Capture-replay vulnerability in dropbox samly allows an attacker to authenticate as the subject of a captured SAML assertion by resubmitting it.
This issue affects samly: from 0.3.0 onward. Affected versions
0.10.0
0.10.1
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
+ 15 more Show less
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0-rc.0
1.0.0-rc.1
1.1.0
1.2.0
1.3.0
1.4.0
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-53425
EEF-CVE-2026-53425
Aug 20, 2026
Missing InResponseTo validation in Samly allows acceptance of unsolicited SAML responses
Critical
Network
Low
None
SummaryInsufficient Verification of Data Authenticity vulnerability in dropbox samly allows an attacker to establish an authenticated session using a SAML response the service provider never requested.
This issue affects samly: from 0.3.0 onward. Affected versions
0.10.0
0.10.1
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
+ 15 more Show less
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0-rc.0
1.0.0-rc.1
1.1.0
1.2.0
1.3.0
1.4.0
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2024-25718
GHSA-h3rw-77w7-92gf
Feb 11, 2024
Samly access control vulnerability
Critical
Network
Low
None
None
In the Samly package before 1.4.0 for Elixir, Fixed in
1.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.2.0
minor
3 CVEs
CVE-2026-53424
EEF-CVE-2026-53424
Aug 20, 2026
Missing one-time-use enforcement in Samly allows replay of SAML bearer assertions
Critical
Network
Low
None
None
SummaryAuthentication Bypass by Capture-replay vulnerability in dropbox samly allows an attacker to authenticate as the subject of a captured SAML assertion by resubmitting it.
This issue affects samly: from 0.3.0 onward. Affected versions
0.10.0
0.10.1
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
+ 15 more Show less
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0-rc.0
1.0.0-rc.1
1.1.0
1.2.0
1.3.0
1.4.0
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-53425
EEF-CVE-2026-53425
Aug 20, 2026
Missing InResponseTo validation in Samly allows acceptance of unsolicited SAML responses
Critical
Network
Low
None
SummaryInsufficient Verification of Data Authenticity vulnerability in dropbox samly allows an attacker to establish an authenticated session using a SAML response the service provider never requested.
This issue affects samly: from 0.3.0 onward. Affected versions
0.10.0
0.10.1
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
+ 15 more Show less
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0-rc.0
1.0.0-rc.1
1.1.0
1.2.0
1.3.0
1.4.0
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2024-25718
GHSA-h3rw-77w7-92gf
Feb 11, 2024
Samly access control vulnerability
Critical
Network
Low
None
None
In the Samly package before 1.4.0 for Elixir, Fixed in
1.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.1.0
minor
3 CVEs
CVE-2026-53424
EEF-CVE-2026-53424
Aug 20, 2026
Missing one-time-use enforcement in Samly allows replay of SAML bearer assertions
Critical
Network
Low
None
None
SummaryAuthentication Bypass by Capture-replay vulnerability in dropbox samly allows an attacker to authenticate as the subject of a captured SAML assertion by resubmitting it.
This issue affects samly: from 0.3.0 onward. Affected versions
0.10.0
0.10.1
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
+ 15 more Show less
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0-rc.0
1.0.0-rc.1
1.1.0
1.2.0
1.3.0
1.4.0
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-53425
EEF-CVE-2026-53425
Aug 20, 2026
Missing InResponseTo validation in Samly allows acceptance of unsolicited SAML responses
Critical
Network
Low
None
SummaryInsufficient Verification of Data Authenticity vulnerability in dropbox samly allows an attacker to establish an authenticated session using a SAML response the service provider never requested.
This issue affects samly: from 0.3.0 onward. Affected versions
0.10.0
0.10.1
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
+ 15 more Show less
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0-rc.0
1.0.0-rc.1
1.1.0
1.2.0
1.3.0
1.4.0
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2024-25718
GHSA-h3rw-77w7-92gf
Feb 11, 2024
Samly access control vulnerability
Critical
Network
Low
None
None
In the Samly package before 1.4.0 for Elixir, Fixed in
1.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.0.0
major
3 CVEs
CVE-2026-53424
EEF-CVE-2026-53424
Aug 20, 2026
Missing one-time-use enforcement in Samly allows replay of SAML bearer assertions
Critical
Network
Low
None
None
SummaryAuthentication Bypass by Capture-replay vulnerability in dropbox samly allows an attacker to authenticate as the subject of a captured SAML assertion by resubmitting it.
This issue affects samly: from 0.3.0 onward. Affected versions
0.10.0
0.10.1
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
+ 15 more Show less
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0-rc.0
1.0.0-rc.1
1.1.0
1.2.0
1.3.0
1.4.0
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-53425
EEF-CVE-2026-53425
Aug 20, 2026
Missing InResponseTo validation in Samly allows acceptance of unsolicited SAML responses
Critical
Network
Low
None
SummaryInsufficient Verification of Data Authenticity vulnerability in dropbox samly allows an attacker to establish an authenticated session using a SAML response the service provider never requested.
This issue affects samly: from 0.3.0 onward. Affected versions
0.10.0
0.10.1
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
+ 15 more Show less
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0-rc.0
1.0.0-rc.1
1.1.0
1.2.0
1.3.0
1.4.0
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2024-25718
GHSA-h3rw-77w7-92gf
Feb 11, 2024
Samly access control vulnerability
Critical
Network
Low
None
None
In the Samly package before 1.4.0 for Elixir, Fixed in
1.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.0.0-rc.1
pre
3 CVEs
CVE-2026-53424
EEF-CVE-2026-53424
Aug 20, 2026
Missing one-time-use enforcement in Samly allows replay of SAML bearer assertions
Critical
Network
Low
None
None
SummaryAuthentication Bypass by Capture-replay vulnerability in dropbox samly allows an attacker to authenticate as the subject of a captured SAML assertion by resubmitting it.
This issue affects samly: from 0.3.0 onward. Affected versions
0.10.0
0.10.1
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
+ 15 more Show less
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0-rc.0
1.0.0-rc.1
1.1.0
1.2.0
1.3.0
1.4.0
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-53425
EEF-CVE-2026-53425
Aug 20, 2026
Missing InResponseTo validation in Samly allows acceptance of unsolicited SAML responses
Critical
Network
Low
None
SummaryInsufficient Verification of Data Authenticity vulnerability in dropbox samly allows an attacker to establish an authenticated session using a SAML response the service provider never requested.
This issue affects samly: from 0.3.0 onward. Affected versions
0.10.0
0.10.1
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
+ 15 more Show less
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0-rc.0
1.0.0-rc.1
1.1.0
1.2.0
1.3.0
1.4.0
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2024-25718
GHSA-h3rw-77w7-92gf
Feb 11, 2024
Samly access control vulnerability
Critical
Network
Low
None
None
In the Samly package before 1.4.0 for Elixir, Fixed in
1.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.0.0-rc.0
pre
3 CVEs
CVE-2026-53424
EEF-CVE-2026-53424
Aug 20, 2026
Missing one-time-use enforcement in Samly allows replay of SAML bearer assertions
Critical
Network
Low
None
None
SummaryAuthentication Bypass by Capture-replay vulnerability in dropbox samly allows an attacker to authenticate as the subject of a captured SAML assertion by resubmitting it.
This issue affects samly: from 0.3.0 onward. Affected versions
0.10.0
0.10.1
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
+ 15 more Show less
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0-rc.0
1.0.0-rc.1
1.1.0
1.2.0
1.3.0
1.4.0
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-53425
EEF-CVE-2026-53425
Aug 20, 2026
Missing InResponseTo validation in Samly allows acceptance of unsolicited SAML responses
Critical
Network
Low
None
SummaryInsufficient Verification of Data Authenticity vulnerability in dropbox samly allows an attacker to establish an authenticated session using a SAML response the service provider never requested.
This issue affects samly: from 0.3.0 onward. Affected versions
0.10.0
0.10.1
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
+ 15 more Show less
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0-rc.0
1.0.0-rc.1
1.1.0
1.2.0
1.3.0
1.4.0
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2024-25718
GHSA-h3rw-77w7-92gf
Feb 11, 2024
Samly access control vulnerability
Critical
Network
Low
None
None
In the Samly package before 1.4.0 for Elixir, Fixed in
1.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.10.1
patch
3 CVEs
CVE-2026-53424
EEF-CVE-2026-53424
Aug 20, 2026
Missing one-time-use enforcement in Samly allows replay of SAML bearer assertions
Critical
Network
Low
None
None
SummaryAuthentication Bypass by Capture-replay vulnerability in dropbox samly allows an attacker to authenticate as the subject of a captured SAML assertion by resubmitting it.
This issue affects samly: from 0.3.0 onward. Affected versions
0.10.0
0.10.1
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
+ 15 more Show less
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0-rc.0
1.0.0-rc.1
1.1.0
1.2.0
1.3.0
1.4.0
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-53425
EEF-CVE-2026-53425
Aug 20, 2026
Missing InResponseTo validation in Samly allows acceptance of unsolicited SAML responses
Critical
Network
Low
None
SummaryInsufficient Verification of Data Authenticity vulnerability in dropbox samly allows an attacker to establish an authenticated session using a SAML response the service provider never requested.
This issue affects samly: from 0.3.0 onward. Affected versions
0.10.0
0.10.1
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
+ 15 more Show less
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0-rc.0
1.0.0-rc.1
1.1.0
1.2.0
1.3.0
1.4.0
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2024-25718
GHSA-h3rw-77w7-92gf
Feb 11, 2024
Samly access control vulnerability
Critical
Network
Low
None
None
In the Samly package before 1.4.0 for Elixir, Fixed in
1.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.10.0
minor
3 CVEs
CVE-2026-53424
EEF-CVE-2026-53424
Aug 20, 2026
Missing one-time-use enforcement in Samly allows replay of SAML bearer assertions
Critical
Network
Low
None
None
SummaryAuthentication Bypass by Capture-replay vulnerability in dropbox samly allows an attacker to authenticate as the subject of a captured SAML assertion by resubmitting it.
This issue affects samly: from 0.3.0 onward. Affected versions
0.10.0
0.10.1
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
+ 15 more Show less
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0-rc.0
1.0.0-rc.1
1.1.0
1.2.0
1.3.0
1.4.0
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-53425
EEF-CVE-2026-53425
Aug 20, 2026
Missing InResponseTo validation in Samly allows acceptance of unsolicited SAML responses
Critical
Network
Low
None
SummaryInsufficient Verification of Data Authenticity vulnerability in dropbox samly allows an attacker to establish an authenticated session using a SAML response the service provider never requested.
This issue affects samly: from 0.3.0 onward. Affected versions
0.10.0
0.10.1
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
+ 15 more Show less
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0-rc.0
1.0.0-rc.1
1.1.0
1.2.0
1.3.0
1.4.0
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2024-25718
GHSA-h3rw-77w7-92gf
Feb 11, 2024
Samly access control vulnerability
Critical
Network
Low
None
None
In the Samly package before 1.4.0 for Elixir, Fixed in
1.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.9.3
patch
3 CVEs
CVE-2026-53424
EEF-CVE-2026-53424
Aug 20, 2026
Missing one-time-use enforcement in Samly allows replay of SAML bearer assertions
Critical
Network
Low
None
None
SummaryAuthentication Bypass by Capture-replay vulnerability in dropbox samly allows an attacker to authenticate as the subject of a captured SAML assertion by resubmitting it.
This issue affects samly: from 0.3.0 onward. Affected versions
0.10.0
0.10.1
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
+ 15 more Show less
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0-rc.0
1.0.0-rc.1
1.1.0
1.2.0
1.3.0
1.4.0
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-53425
EEF-CVE-2026-53425
Aug 20, 2026
Missing InResponseTo validation in Samly allows acceptance of unsolicited SAML responses
Critical
Network
Low
None
SummaryInsufficient Verification of Data Authenticity vulnerability in dropbox samly allows an attacker to establish an authenticated session using a SAML response the service provider never requested.
This issue affects samly: from 0.3.0 onward. Affected versions
0.10.0
0.10.1
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
+ 15 more Show less
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0-rc.0
1.0.0-rc.1
1.1.0
1.2.0
1.3.0
1.4.0
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2024-25718
GHSA-h3rw-77w7-92gf
Feb 11, 2024
Samly access control vulnerability
Critical
Network
Low
None
None
In the Samly package before 1.4.0 for Elixir, Fixed in
1.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.9.2
patch
3 CVEs
CVE-2026-53424
EEF-CVE-2026-53424
Aug 20, 2026
Missing one-time-use enforcement in Samly allows replay of SAML bearer assertions
Critical
Network
Low
None
None
SummaryAuthentication Bypass by Capture-replay vulnerability in dropbox samly allows an attacker to authenticate as the subject of a captured SAML assertion by resubmitting it.
This issue affects samly: from 0.3.0 onward. Affected versions
0.10.0
0.10.1
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
+ 15 more Show less
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0-rc.0
1.0.0-rc.1
1.1.0
1.2.0
1.3.0
1.4.0
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-53425
EEF-CVE-2026-53425
Aug 20, 2026
Missing InResponseTo validation in Samly allows acceptance of unsolicited SAML responses
Critical
Network
Low
None
SummaryInsufficient Verification of Data Authenticity vulnerability in dropbox samly allows an attacker to establish an authenticated session using a SAML response the service provider never requested.
This issue affects samly: from 0.3.0 onward. Affected versions
0.10.0
0.10.1
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
+ 15 more Show less
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0-rc.0
1.0.0-rc.1
1.1.0
1.2.0
1.3.0
1.4.0
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2024-25718
GHSA-h3rw-77w7-92gf
Feb 11, 2024
Samly access control vulnerability
Critical
Network
Low
None
None
In the Samly package before 1.4.0 for Elixir, Fixed in
1.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.9.1
patch
3 CVEs
CVE-2026-53424
EEF-CVE-2026-53424
Aug 20, 2026
Missing one-time-use enforcement in Samly allows replay of SAML bearer assertions
Critical
Network
Low
None
None
SummaryAuthentication Bypass by Capture-replay vulnerability in dropbox samly allows an attacker to authenticate as the subject of a captured SAML assertion by resubmitting it.
This issue affects samly: from 0.3.0 onward. Affected versions
0.10.0
0.10.1
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
+ 15 more Show less
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0-rc.0
1.0.0-rc.1
1.1.0
1.2.0
1.3.0
1.4.0
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-53425
EEF-CVE-2026-53425
Aug 20, 2026
Missing InResponseTo validation in Samly allows acceptance of unsolicited SAML responses
Critical
Network
Low
None
SummaryInsufficient Verification of Data Authenticity vulnerability in dropbox samly allows an attacker to establish an authenticated session using a SAML response the service provider never requested.
This issue affects samly: from 0.3.0 onward. Affected versions
0.10.0
0.10.1
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
+ 15 more Show less
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0-rc.0
1.0.0-rc.1
1.1.0
1.2.0
1.3.0
1.4.0
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2024-25718
GHSA-h3rw-77w7-92gf
Feb 11, 2024
Samly access control vulnerability
Critical
Network
Low
None
None
In the Samly package before 1.4.0 for Elixir, Fixed in
1.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.9.0
minor
3 CVEs
CVE-2026-53424
EEF-CVE-2026-53424
Aug 20, 2026
Missing one-time-use enforcement in Samly allows replay of SAML bearer assertions
Critical
Network
Low
None
None
SummaryAuthentication Bypass by Capture-replay vulnerability in dropbox samly allows an attacker to authenticate as the subject of a captured SAML assertion by resubmitting it.
This issue affects samly: from 0.3.0 onward. Affected versions
0.10.0
0.10.1
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
+ 15 more Show less
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0-rc.0
1.0.0-rc.1
1.1.0
1.2.0
1.3.0
1.4.0
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-53425
EEF-CVE-2026-53425
Aug 20, 2026
Missing InResponseTo validation in Samly allows acceptance of unsolicited SAML responses
Critical
Network
Low
None
SummaryInsufficient Verification of Data Authenticity vulnerability in dropbox samly allows an attacker to establish an authenticated session using a SAML response the service provider never requested.
This issue affects samly: from 0.3.0 onward. Affected versions
0.10.0
0.10.1
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
+ 15 more Show less
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0-rc.0
1.0.0-rc.1
1.1.0
1.2.0
1.3.0
1.4.0
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2024-25718
GHSA-h3rw-77w7-92gf
Feb 11, 2024
Samly access control vulnerability
Critical
Network
Low
None
None
In the Samly package before 1.4.0 for Elixir, Fixed in
1.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.8.4
patch
3 CVEs
CVE-2026-53424
EEF-CVE-2026-53424
Aug 20, 2026
Missing one-time-use enforcement in Samly allows replay of SAML bearer assertions
Critical
Network
Low
None
None
SummaryAuthentication Bypass by Capture-replay vulnerability in dropbox samly allows an attacker to authenticate as the subject of a captured SAML assertion by resubmitting it.
This issue affects samly: from 0.3.0 onward. Affected versions
0.10.0
0.10.1
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
+ 15 more Show less
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0-rc.0
1.0.0-rc.1
1.1.0
1.2.0
1.3.0
1.4.0
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-53425
EEF-CVE-2026-53425
Aug 20, 2026
Missing InResponseTo validation in Samly allows acceptance of unsolicited SAML responses
Critical
Network
Low
None
SummaryInsufficient Verification of Data Authenticity vulnerability in dropbox samly allows an attacker to establish an authenticated session using a SAML response the service provider never requested.
This issue affects samly: from 0.3.0 onward. Affected versions
0.10.0
0.10.1
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
+ 15 more Show less
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0-rc.0
1.0.0-rc.1
1.1.0
1.2.0
1.3.0
1.4.0
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2024-25718
GHSA-h3rw-77w7-92gf
Feb 11, 2024
Samly access control vulnerability
Critical
Network
Low
None
None
In the Samly package before 1.4.0 for Elixir, Fixed in
1.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.8.3
patch
3 CVEs
CVE-2026-53424
EEF-CVE-2026-53424
Aug 20, 2026
Missing one-time-use enforcement in Samly allows replay of SAML bearer assertions
Critical
Network
Low
None
None
SummaryAuthentication Bypass by Capture-replay vulnerability in dropbox samly allows an attacker to authenticate as the subject of a captured SAML assertion by resubmitting it.
This issue affects samly: from 0.3.0 onward. Affected versions
0.10.0
0.10.1
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
+ 15 more Show less
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0-rc.0
1.0.0-rc.1
1.1.0
1.2.0
1.3.0
1.4.0
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-53425
EEF-CVE-2026-53425
Aug 20, 2026
Missing InResponseTo validation in Samly allows acceptance of unsolicited SAML responses
Critical
Network
Low
None
SummaryInsufficient Verification of Data Authenticity vulnerability in dropbox samly allows an attacker to establish an authenticated session using a SAML response the service provider never requested.
This issue affects samly: from 0.3.0 onward. Affected versions
0.10.0
0.10.1
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
+ 15 more Show less
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0-rc.0
1.0.0-rc.1
1.1.0
1.2.0
1.3.0
1.4.0
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2024-25718
GHSA-h3rw-77w7-92gf
Feb 11, 2024
Samly access control vulnerability
Critical
Network
Low
None
None
In the Samly package before 1.4.0 for Elixir, Fixed in
1.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.8.2
patch
3 CVEs
CVE-2026-53424
EEF-CVE-2026-53424
Aug 20, 2026
Missing one-time-use enforcement in Samly allows replay of SAML bearer assertions
Critical
Network
Low
None
None
SummaryAuthentication Bypass by Capture-replay vulnerability in dropbox samly allows an attacker to authenticate as the subject of a captured SAML assertion by resubmitting it.
This issue affects samly: from 0.3.0 onward. Affected versions
0.10.0
0.10.1
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
+ 15 more Show less
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0-rc.0
1.0.0-rc.1
1.1.0
1.2.0
1.3.0
1.4.0
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-53425
EEF-CVE-2026-53425
Aug 20, 2026
Missing InResponseTo validation in Samly allows acceptance of unsolicited SAML responses
Critical
Network
Low
None
SummaryInsufficient Verification of Data Authenticity vulnerability in dropbox samly allows an attacker to establish an authenticated session using a SAML response the service provider never requested.
This issue affects samly: from 0.3.0 onward. Affected versions
0.10.0
0.10.1
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
+ 15 more Show less
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0-rc.0
1.0.0-rc.1
1.1.0
1.2.0
1.3.0
1.4.0
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2024-25718
GHSA-h3rw-77w7-92gf
Feb 11, 2024
Samly access control vulnerability
Critical
Network
Low
None
None
In the Samly package before 1.4.0 for Elixir, Fixed in
1.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.8.1
patch
3 CVEs
CVE-2026-53424
EEF-CVE-2026-53424
Aug 20, 2026
Missing one-time-use enforcement in Samly allows replay of SAML bearer assertions
Critical
Network
Low
None
None
SummaryAuthentication Bypass by Capture-replay vulnerability in dropbox samly allows an attacker to authenticate as the subject of a captured SAML assertion by resubmitting it.
This issue affects samly: from 0.3.0 onward. Affected versions
0.10.0
0.10.1
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
+ 15 more Show less
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0-rc.0
1.0.0-rc.1
1.1.0
1.2.0
1.3.0
1.4.0
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-53425
EEF-CVE-2026-53425
Aug 20, 2026
Missing InResponseTo validation in Samly allows acceptance of unsolicited SAML responses
Critical
Network
Low
None
SummaryInsufficient Verification of Data Authenticity vulnerability in dropbox samly allows an attacker to establish an authenticated session using a SAML response the service provider never requested.
This issue affects samly: from 0.3.0 onward. Affected versions
0.10.0
0.10.1
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
+ 15 more Show less
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0-rc.0
1.0.0-rc.1
1.1.0
1.2.0
1.3.0
1.4.0
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2024-25718
GHSA-h3rw-77w7-92gf
Feb 11, 2024
Samly access control vulnerability
Critical
Network
Low
None
None
In the Samly package before 1.4.0 for Elixir, Fixed in
1.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.8.0
minor
3 CVEs
CVE-2026-53424
EEF-CVE-2026-53424
Aug 20, 2026
Missing one-time-use enforcement in Samly allows replay of SAML bearer assertions
Critical
Network
Low
None
None
SummaryAuthentication Bypass by Capture-replay vulnerability in dropbox samly allows an attacker to authenticate as the subject of a captured SAML assertion by resubmitting it.
This issue affects samly: from 0.3.0 onward. Affected versions
0.10.0
0.10.1
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
+ 15 more Show less
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0-rc.0
1.0.0-rc.1
1.1.0
1.2.0
1.3.0
1.4.0
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-53425
EEF-CVE-2026-53425
Aug 20, 2026
Missing InResponseTo validation in Samly allows acceptance of unsolicited SAML responses
Critical
Network
Low
None
SummaryInsufficient Verification of Data Authenticity vulnerability in dropbox samly allows an attacker to establish an authenticated session using a SAML response the service provider never requested.
This issue affects samly: from 0.3.0 onward. Affected versions
0.10.0
0.10.1
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
+ 15 more Show less
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0-rc.0
1.0.0-rc.1
1.1.0
1.2.0
1.3.0
1.4.0
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2024-25718
GHSA-h3rw-77w7-92gf
Feb 11, 2024
Samly access control vulnerability
Critical
Network
Low
None
None
In the Samly package before 1.4.0 for Elixir, Fixed in
1.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.7.2
patch
3 CVEs
CVE-2026-53424
EEF-CVE-2026-53424
Aug 20, 2026
Missing one-time-use enforcement in Samly allows replay of SAML bearer assertions
Critical
Network
Low
None
None
SummaryAuthentication Bypass by Capture-replay vulnerability in dropbox samly allows an attacker to authenticate as the subject of a captured SAML assertion by resubmitting it.
This issue affects samly: from 0.3.0 onward. Affected versions
0.10.0
0.10.1
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
+ 15 more Show less
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0-rc.0
1.0.0-rc.1
1.1.0
1.2.0
1.3.0
1.4.0
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-53425
EEF-CVE-2026-53425
Aug 20, 2026
Missing InResponseTo validation in Samly allows acceptance of unsolicited SAML responses
Critical
Network
Low
None
SummaryInsufficient Verification of Data Authenticity vulnerability in dropbox samly allows an attacker to establish an authenticated session using a SAML response the service provider never requested.
This issue affects samly: from 0.3.0 onward. Affected versions
0.10.0
0.10.1
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
+ 15 more Show less
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0-rc.0
1.0.0-rc.1
1.1.0
1.2.0
1.3.0
1.4.0
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2024-25718
GHSA-h3rw-77w7-92gf
Feb 11, 2024
Samly access control vulnerability
Critical
Network
Low
None
None
In the Samly package before 1.4.0 for Elixir, Fixed in
1.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.7.1
patch
3 CVEs
CVE-2026-53424
EEF-CVE-2026-53424
Aug 20, 2026
Missing one-time-use enforcement in Samly allows replay of SAML bearer assertions
Critical
Network
Low
None
None
SummaryAuthentication Bypass by Capture-replay vulnerability in dropbox samly allows an attacker to authenticate as the subject of a captured SAML assertion by resubmitting it.
This issue affects samly: from 0.3.0 onward. Affected versions
0.10.0
0.10.1
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
+ 15 more Show less
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0-rc.0
1.0.0-rc.1
1.1.0
1.2.0
1.3.0
1.4.0
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-53425
EEF-CVE-2026-53425
Aug 20, 2026
Missing InResponseTo validation in Samly allows acceptance of unsolicited SAML responses
Critical
Network
Low
None
SummaryInsufficient Verification of Data Authenticity vulnerability in dropbox samly allows an attacker to establish an authenticated session using a SAML response the service provider never requested.
This issue affects samly: from 0.3.0 onward. Affected versions
0.10.0
0.10.1
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
+ 15 more Show less
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0-rc.0
1.0.0-rc.1
1.1.0
1.2.0
1.3.0
1.4.0
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2024-25718
GHSA-h3rw-77w7-92gf
Feb 11, 2024
Samly access control vulnerability
Critical
Network
Low
None
None
In the Samly package before 1.4.0 for Elixir, Fixed in
1.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.7.0
minor
3 CVEs
CVE-2026-53424
EEF-CVE-2026-53424
Aug 20, 2026
Missing one-time-use enforcement in Samly allows replay of SAML bearer assertions
Critical
Network
Low
None
None
SummaryAuthentication Bypass by Capture-replay vulnerability in dropbox samly allows an attacker to authenticate as the subject of a captured SAML assertion by resubmitting it.
This issue affects samly: from 0.3.0 onward. Affected versions
0.10.0
0.10.1
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
+ 15 more Show less
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0-rc.0
1.0.0-rc.1
1.1.0
1.2.0
1.3.0
1.4.0
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-53425
EEF-CVE-2026-53425
Aug 20, 2026
Missing InResponseTo validation in Samly allows acceptance of unsolicited SAML responses
Critical
Network
Low
None
SummaryInsufficient Verification of Data Authenticity vulnerability in dropbox samly allows an attacker to establish an authenticated session using a SAML response the service provider never requested.
This issue affects samly: from 0.3.0 onward. Affected versions
0.10.0
0.10.1
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
+ 15 more Show less
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0-rc.0
1.0.0-rc.1
1.1.0
1.2.0
1.3.0
1.4.0
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2024-25718
GHSA-h3rw-77w7-92gf
Feb 11, 2024
Samly access control vulnerability
Critical
Network
Low
None
None
In the Samly package before 1.4.0 for Elixir, Fixed in
1.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.6.3
patch
3 CVEs
CVE-2026-53424
EEF-CVE-2026-53424
Aug 20, 2026
Missing one-time-use enforcement in Samly allows replay of SAML bearer assertions
Critical
Network
Low
None
None
SummaryAuthentication Bypass by Capture-replay vulnerability in dropbox samly allows an attacker to authenticate as the subject of a captured SAML assertion by resubmitting it.
This issue affects samly: from 0.3.0 onward. Affected versions
0.10.0
0.10.1
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
+ 15 more Show less
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0-rc.0
1.0.0-rc.1
1.1.0
1.2.0
1.3.0
1.4.0
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-53425
EEF-CVE-2026-53425
Aug 20, 2026
Missing InResponseTo validation in Samly allows acceptance of unsolicited SAML responses
Critical
Network
Low
None
SummaryInsufficient Verification of Data Authenticity vulnerability in dropbox samly allows an attacker to establish an authenticated session using a SAML response the service provider never requested.
This issue affects samly: from 0.3.0 onward. Affected versions
0.10.0
0.10.1
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
+ 15 more Show less
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0-rc.0
1.0.0-rc.1
1.1.0
1.2.0
1.3.0
1.4.0
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2024-25718
GHSA-h3rw-77w7-92gf
Feb 11, 2024
Samly access control vulnerability
Critical
Network
Low
None
None
In the Samly package before 1.4.0 for Elixir, Fixed in
1.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.6.2
patch
3 CVEs
CVE-2026-53424
EEF-CVE-2026-53424
Aug 20, 2026
Missing one-time-use enforcement in Samly allows replay of SAML bearer assertions
Critical
Network
Low
None
None
SummaryAuthentication Bypass by Capture-replay vulnerability in dropbox samly allows an attacker to authenticate as the subject of a captured SAML assertion by resubmitting it.
This issue affects samly: from 0.3.0 onward. Affected versions
0.10.0
0.10.1
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
+ 15 more Show less
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0-rc.0
1.0.0-rc.1
1.1.0
1.2.0
1.3.0
1.4.0
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-53425
EEF-CVE-2026-53425
Aug 20, 2026
Missing InResponseTo validation in Samly allows acceptance of unsolicited SAML responses
Critical
Network
Low
None
SummaryInsufficient Verification of Data Authenticity vulnerability in dropbox samly allows an attacker to establish an authenticated session using a SAML response the service provider never requested.
This issue affects samly: from 0.3.0 onward. Affected versions
0.10.0
0.10.1
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
+ 15 more Show less
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0-rc.0
1.0.0-rc.1
1.1.0
1.2.0
1.3.0
1.4.0
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2024-25718
GHSA-h3rw-77w7-92gf
Feb 11, 2024
Samly access control vulnerability
Critical
Network
Low
None
None
In the Samly package before 1.4.0 for Elixir, Fixed in
1.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.6.1
patch
3 CVEs
CVE-2026-53424
EEF-CVE-2026-53424
Aug 20, 2026
Missing one-time-use enforcement in Samly allows replay of SAML bearer assertions
Critical
Network
Low
None
None
SummaryAuthentication Bypass by Capture-replay vulnerability in dropbox samly allows an attacker to authenticate as the subject of a captured SAML assertion by resubmitting it.
This issue affects samly: from 0.3.0 onward. Affected versions
0.10.0
0.10.1
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
+ 15 more Show less
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0-rc.0
1.0.0-rc.1
1.1.0
1.2.0
1.3.0
1.4.0
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-53425
EEF-CVE-2026-53425
Aug 20, 2026
Missing InResponseTo validation in Samly allows acceptance of unsolicited SAML responses
Critical
Network
Low
None
SummaryInsufficient Verification of Data Authenticity vulnerability in dropbox samly allows an attacker to establish an authenticated session using a SAML response the service provider never requested.
This issue affects samly: from 0.3.0 onward. Affected versions
0.10.0
0.10.1
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
+ 15 more Show less
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0-rc.0
1.0.0-rc.1
1.1.0
1.2.0
1.3.0
1.4.0
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2024-25718
GHSA-h3rw-77w7-92gf
Feb 11, 2024
Samly access control vulnerability
Critical
Network
Low
None
None
In the Samly package before 1.4.0 for Elixir, Fixed in
1.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.6.0
minor
3 CVEs
CVE-2026-53424
EEF-CVE-2026-53424
Aug 20, 2026
Missing one-time-use enforcement in Samly allows replay of SAML bearer assertions
Critical
Network
Low
None
None
SummaryAuthentication Bypass by Capture-replay vulnerability in dropbox samly allows an attacker to authenticate as the subject of a captured SAML assertion by resubmitting it.
This issue affects samly: from 0.3.0 onward. Affected versions
0.10.0
0.10.1
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
+ 15 more Show less
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0-rc.0
1.0.0-rc.1
1.1.0
1.2.0
1.3.0
1.4.0
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-53425
EEF-CVE-2026-53425
Aug 20, 2026
Missing InResponseTo validation in Samly allows acceptance of unsolicited SAML responses
Critical
Network
Low
None
SummaryInsufficient Verification of Data Authenticity vulnerability in dropbox samly allows an attacker to establish an authenticated session using a SAML response the service provider never requested.
This issue affects samly: from 0.3.0 onward. Affected versions
0.10.0
0.10.1
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
+ 15 more Show less
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0-rc.0
1.0.0-rc.1
1.1.0
1.2.0
1.3.0
1.4.0
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2024-25718
GHSA-h3rw-77w7-92gf
Feb 11, 2024
Samly access control vulnerability
Critical
Network
Low
None
None
In the Samly package before 1.4.0 for Elixir, Fixed in
1.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.5.0
minor
3 CVEs
CVE-2026-53424
EEF-CVE-2026-53424
Aug 20, 2026
Missing one-time-use enforcement in Samly allows replay of SAML bearer assertions
Critical
Network
Low
None
None
SummaryAuthentication Bypass by Capture-replay vulnerability in dropbox samly allows an attacker to authenticate as the subject of a captured SAML assertion by resubmitting it.
This issue affects samly: from 0.3.0 onward. Affected versions
0.10.0
0.10.1
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
+ 15 more Show less
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0-rc.0
1.0.0-rc.1
1.1.0
1.2.0
1.3.0
1.4.0
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-53425
EEF-CVE-2026-53425
Aug 20, 2026
Missing InResponseTo validation in Samly allows acceptance of unsolicited SAML responses
Critical
Network
Low
None
SummaryInsufficient Verification of Data Authenticity vulnerability in dropbox samly allows an attacker to establish an authenticated session using a SAML response the service provider never requested.
This issue affects samly: from 0.3.0 onward. Affected versions
0.10.0
0.10.1
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
+ 15 more Show less
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0-rc.0
1.0.0-rc.1
1.1.0
1.2.0
1.3.0
1.4.0
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2024-25718
GHSA-h3rw-77w7-92gf
Feb 11, 2024
Samly access control vulnerability
Critical
Network
Low
None
None
In the Samly package before 1.4.0 for Elixir, Fixed in
1.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.4.0
minor
3 CVEs
CVE-2026-53424
EEF-CVE-2026-53424
Aug 20, 2026
Missing one-time-use enforcement in Samly allows replay of SAML bearer assertions
Critical
Network
Low
None
None
SummaryAuthentication Bypass by Capture-replay vulnerability in dropbox samly allows an attacker to authenticate as the subject of a captured SAML assertion by resubmitting it.
This issue affects samly: from 0.3.0 onward. Affected versions
0.10.0
0.10.1
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
+ 15 more Show less
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0-rc.0
1.0.0-rc.1
1.1.0
1.2.0
1.3.0
1.4.0
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-53425
EEF-CVE-2026-53425
Aug 20, 2026
Missing InResponseTo validation in Samly allows acceptance of unsolicited SAML responses
Critical
Network
Low
None
SummaryInsufficient Verification of Data Authenticity vulnerability in dropbox samly allows an attacker to establish an authenticated session using a SAML response the service provider never requested.
This issue affects samly: from 0.3.0 onward. Affected versions
0.10.0
0.10.1
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
+ 15 more Show less
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0-rc.0
1.0.0-rc.1
1.1.0
1.2.0
1.3.0
1.4.0
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2024-25718
GHSA-h3rw-77w7-92gf
Feb 11, 2024
Samly access control vulnerability
Critical
Network
Low
None
None
In the Samly package before 1.4.0 for Elixir, Fixed in
1.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.1.2
initial
1 CVE
CVE-2024-25718
GHSA-h3rw-77w7-92gf
Feb 11, 2024
Samly access control vulnerability
Critical
Network
Low
None
None
In the Samly package before 1.4.0 for Elixir, Fixed in
1.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev |