simplesamlphp/simplesamlphp-module-casserver
CAS 1.0 and 2.0 compliant CAS server module for simpleSAMLphp
Activity
- Latest release
- 1mo ago
- Total releases
- 17
- Cadence
- ~2 months
- Last 12 months
- 8
Reach
- Stars
- 7
Details
- License
- unknown
- First release
- Aug 01, 2016
| Version | Released | |
|---|---|---|
v7.0.5
patch
|
v7.0.5
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
v7.0.4
patch
|
v7.0.4
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
v7.0.3
patch
|
v7.0.3
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
v7.0.2
patch
1 CVE
CVE-2026-46491
GHSA-jrrg-99xh-5j2q
May 15, 2026
SimpleSAMLphp casserver FileSystemTicketStore path traversal allows out-of-ticket-directory read/unserialize and conditional deletion
8.6
/ 10
High
Network
Low
None
None
Unchanged
Low
High
Low
Summary
In deployments using PreconditionsThe demonstrated issue requires:
The attacker does not need administrator access to SimpleSAMLphp. ImpactAffected deployments can allow remote attackers to escape the configured CAS ticket directory through public ticket validation inputs. Confirmed impact:
The file deletion impact depends on filesystem permissions of the PHP process. In realistic deployments, this can destroy CAS tickets, serialized SimpleSAMLphp runtime/cache files, or other writable files whose contents can be unserialized into a value accepted by the The Affected versions
v6.0.0
v6.1.0
v6.1.1
v6.1.2
v6.2.0
v6.2.1
v6.3.0
v6.3.1
v7.0.0
v7.0.0-rc1
v7.0.0-rc2
v7.0.0-rc3
+ 2 more Show less
v7.0.1
v7.0.2
Fixed in
7.0.3
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v7.0.1
patch
1 CVE
CVE-2026-46491
GHSA-jrrg-99xh-5j2q
May 15, 2026
SimpleSAMLphp casserver FileSystemTicketStore path traversal allows out-of-ticket-directory read/unserialize and conditional deletion
8.6
/ 10
High
Network
Low
None
None
Unchanged
Low
High
Low
Summary
In deployments using PreconditionsThe demonstrated issue requires:
The attacker does not need administrator access to SimpleSAMLphp. ImpactAffected deployments can allow remote attackers to escape the configured CAS ticket directory through public ticket validation inputs. Confirmed impact:
The file deletion impact depends on filesystem permissions of the PHP process. In realistic deployments, this can destroy CAS tickets, serialized SimpleSAMLphp runtime/cache files, or other writable files whose contents can be unserialized into a value accepted by the The Affected versions
v6.0.0
v6.1.0
v6.1.1
v6.1.2
v6.2.0
v6.2.1
v6.3.0
v6.3.1
v7.0.0
v7.0.0-rc1
v7.0.0-rc2
v7.0.0-rc3
+ 2 more Show less
v7.0.1
v7.0.2
Fixed in
7.0.3
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v7.0.0
major
1 CVE
CVE-2026-46491
GHSA-jrrg-99xh-5j2q
May 15, 2026
SimpleSAMLphp casserver FileSystemTicketStore path traversal allows out-of-ticket-directory read/unserialize and conditional deletion
8.6
/ 10
High
Network
Low
None
None
Unchanged
Low
High
Low
Summary
In deployments using PreconditionsThe demonstrated issue requires:
The attacker does not need administrator access to SimpleSAMLphp. ImpactAffected deployments can allow remote attackers to escape the configured CAS ticket directory through public ticket validation inputs. Confirmed impact:
The file deletion impact depends on filesystem permissions of the PHP process. In realistic deployments, this can destroy CAS tickets, serialized SimpleSAMLphp runtime/cache files, or other writable files whose contents can be unserialized into a value accepted by the The Affected versions
v6.0.0
v6.1.0
v6.1.1
v6.1.2
v6.2.0
v6.2.1
v6.3.0
v6.3.1
v7.0.0
v7.0.0-rc1
v7.0.0-rc2
v7.0.0-rc3
+ 2 more Show less
v7.0.1
v7.0.2
Fixed in
7.0.3
References
Updated Sep 10, 2026 · Source: OSV.dev |
v7.0.0
major
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
v6.3.1
patch
1 CVE
CVE-2026-46491
GHSA-jrrg-99xh-5j2q
May 15, 2026
SimpleSAMLphp casserver FileSystemTicketStore path traversal allows out-of-ticket-directory read/unserialize and conditional deletion
8.6
/ 10
High
Network
Low
None
None
Unchanged
Low
High
Low
Summary
In deployments using PreconditionsThe demonstrated issue requires:
The attacker does not need administrator access to SimpleSAMLphp. ImpactAffected deployments can allow remote attackers to escape the configured CAS ticket directory through public ticket validation inputs. Confirmed impact:
The file deletion impact depends on filesystem permissions of the PHP process. In realistic deployments, this can destroy CAS tickets, serialized SimpleSAMLphp runtime/cache files, or other writable files whose contents can be unserialized into a value accepted by the The Affected versions
v6.0.0
v6.1.0
v6.1.1
v6.1.2
v6.2.0
v6.2.1
v6.3.0
v6.3.1
v7.0.0
v7.0.0-rc1
v7.0.0-rc2
v7.0.0-rc3
+ 2 more Show less
v7.0.1
v7.0.2
Fixed in
7.0.3
References
Updated Sep 10, 2026 · Source: OSV.dev |
v6.3.1
patch
Dependencies (6)
Changelog
Compare changes
|
|
v6.2.1
patch
2 CVEs
CVE-2026-46491
GHSA-jrrg-99xh-5j2q
May 15, 2026
SimpleSAMLphp casserver FileSystemTicketStore path traversal allows out-of-ticket-directory read/unserialize and conditional deletion
8.6
/ 10
High
Network
Low
None
None
Unchanged
Low
High
Low
Summary
In deployments using PreconditionsThe demonstrated issue requires:
The attacker does not need administrator access to SimpleSAMLphp. ImpactAffected deployments can allow remote attackers to escape the configured CAS ticket directory through public ticket validation inputs. Confirmed impact:
The file deletion impact depends on filesystem permissions of the PHP process. In realistic deployments, this can destroy CAS tickets, serialized SimpleSAMLphp runtime/cache files, or other writable files whose contents can be unserialized into a value accepted by the The Affected versions
v6.0.0
v6.1.0
v6.1.1
v6.1.2
v6.2.0
v6.2.1
v6.3.0
v6.3.1
v7.0.0
v7.0.0-rc1
v7.0.0-rc2
v7.0.0-rc3
+ 2 more Show less
v7.0.1
v7.0.2
Fixed in
7.0.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-65954
GHSA-cvrm-5hp6-h523
May 15, 2026
SimpleSAMLphp casserver: Open Redirect in logout
4.7
/ 10
Medium
Network
Low
None
Required
Changed
None
Low
None
SummaryThe logout endpoint accepts a There are a number of other things broken with logout in 7 (cas v3 uses a different query parameters, etc) Detailshttps://github.com/simplesamlphp/simplesamlphp-module-casserver/blob/21418f7efbea8c4f078fd4a7d1b9eacf94dd4941/src/Controller/LogoutController.php#L104 Previous module checked the url against the valid service urls. PoCThe docker instructions from the README.md run an image with a vulnerable config. Accessing https://localhost/cas/logout?url=https://google.com will redirect to Google ImpactImpacted configs have
and are most impacted if they also have
Affected versions
v7.0.0-rc1
v7.0.0-rc2
v7.0.0-rc3
v6.0.0
v6.1.0
v6.1.1
v6.1.2
v6.2.0
v6.2.1
v6.3.0
Fixed in
6.3.1
7.0.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v7.0.0-rc3
pre
2 CVEs
CVE-2026-46491
GHSA-jrrg-99xh-5j2q
May 15, 2026
SimpleSAMLphp casserver FileSystemTicketStore path traversal allows out-of-ticket-directory read/unserialize and conditional deletion
8.6
/ 10
High
Network
Low
None
None
Unchanged
Low
High
Low
Summary
In deployments using PreconditionsThe demonstrated issue requires:
The attacker does not need administrator access to SimpleSAMLphp. ImpactAffected deployments can allow remote attackers to escape the configured CAS ticket directory through public ticket validation inputs. Confirmed impact:
The file deletion impact depends on filesystem permissions of the PHP process. In realistic deployments, this can destroy CAS tickets, serialized SimpleSAMLphp runtime/cache files, or other writable files whose contents can be unserialized into a value accepted by the The Affected versions
v6.0.0
v6.1.0
v6.1.1
v6.1.2
v6.2.0
v6.2.1
v6.3.0
v6.3.1
v7.0.0
v7.0.0-rc1
v7.0.0-rc2
v7.0.0-rc3
+ 2 more Show less
v7.0.1
v7.0.2
Fixed in
7.0.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-65954
GHSA-cvrm-5hp6-h523
May 15, 2026
SimpleSAMLphp casserver: Open Redirect in logout
4.7
/ 10
Medium
Network
Low
None
Required
Changed
None
Low
None
SummaryThe logout endpoint accepts a There are a number of other things broken with logout in 7 (cas v3 uses a different query parameters, etc) Detailshttps://github.com/simplesamlphp/simplesamlphp-module-casserver/blob/21418f7efbea8c4f078fd4a7d1b9eacf94dd4941/src/Controller/LogoutController.php#L104 Previous module checked the url against the valid service urls. PoCThe docker instructions from the README.md run an image with a vulnerable config. Accessing https://localhost/cas/logout?url=https://google.com will redirect to Google ImpactImpacted configs have
and are most impacted if they also have
Affected versions
v7.0.0-rc1
v7.0.0-rc2
v7.0.0-rc3
v6.0.0
v6.1.0
v6.1.1
v6.1.2
v6.2.0
v6.2.1
v6.3.0
Fixed in
6.3.1
7.0.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
v7.0.0-rc3
pre
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
v6.3.0
minor
2 CVEs
CVE-2026-46491
GHSA-jrrg-99xh-5j2q
May 15, 2026
SimpleSAMLphp casserver FileSystemTicketStore path traversal allows out-of-ticket-directory read/unserialize and conditional deletion
8.6
/ 10
High
Network
Low
None
None
Unchanged
Low
High
Low
Summary
In deployments using PreconditionsThe demonstrated issue requires:
The attacker does not need administrator access to SimpleSAMLphp. ImpactAffected deployments can allow remote attackers to escape the configured CAS ticket directory through public ticket validation inputs. Confirmed impact:
The file deletion impact depends on filesystem permissions of the PHP process. In realistic deployments, this can destroy CAS tickets, serialized SimpleSAMLphp runtime/cache files, or other writable files whose contents can be unserialized into a value accepted by the The Affected versions
v6.0.0
v6.1.0
v6.1.1
v6.1.2
v6.2.0
v6.2.1
v6.3.0
v6.3.1
v7.0.0
v7.0.0-rc1
v7.0.0-rc2
v7.0.0-rc3
+ 2 more Show less
v7.0.1
v7.0.2
Fixed in
7.0.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-65954
GHSA-cvrm-5hp6-h523
May 15, 2026
SimpleSAMLphp casserver: Open Redirect in logout
4.7
/ 10
Medium
Network
Low
None
Required
Changed
None
Low
None
SummaryThe logout endpoint accepts a There are a number of other things broken with logout in 7 (cas v3 uses a different query parameters, etc) Detailshttps://github.com/simplesamlphp/simplesamlphp-module-casserver/blob/21418f7efbea8c4f078fd4a7d1b9eacf94dd4941/src/Controller/LogoutController.php#L104 Previous module checked the url against the valid service urls. PoCThe docker instructions from the README.md run an image with a vulnerable config. Accessing https://localhost/cas/logout?url=https://google.com will redirect to Google ImpactImpacted configs have
and are most impacted if they also have
Affected versions
v7.0.0-rc1
v7.0.0-rc2
v7.0.0-rc3
v6.0.0
v6.1.0
v6.1.1
v6.1.2
v6.2.0
v6.2.1
v6.3.0
Fixed in
6.3.1
7.0.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v7.0.0-rc2
pre
2 CVEs
CVE-2026-46491
GHSA-jrrg-99xh-5j2q
May 15, 2026
SimpleSAMLphp casserver FileSystemTicketStore path traversal allows out-of-ticket-directory read/unserialize and conditional deletion
8.6
/ 10
High
Network
Low
None
None
Unchanged
Low
High
Low
Summary
In deployments using PreconditionsThe demonstrated issue requires:
The attacker does not need administrator access to SimpleSAMLphp. ImpactAffected deployments can allow remote attackers to escape the configured CAS ticket directory through public ticket validation inputs. Confirmed impact:
The file deletion impact depends on filesystem permissions of the PHP process. In realistic deployments, this can destroy CAS tickets, serialized SimpleSAMLphp runtime/cache files, or other writable files whose contents can be unserialized into a value accepted by the The Affected versions
v6.0.0
v6.1.0
v6.1.1
v6.1.2
v6.2.0
v6.2.1
v6.3.0
v6.3.1
v7.0.0
v7.0.0-rc1
v7.0.0-rc2
v7.0.0-rc3
+ 2 more Show less
v7.0.1
v7.0.2
Fixed in
7.0.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-65954
GHSA-cvrm-5hp6-h523
May 15, 2026
SimpleSAMLphp casserver: Open Redirect in logout
4.7
/ 10
Medium
Network
Low
None
Required
Changed
None
Low
None
SummaryThe logout endpoint accepts a There are a number of other things broken with logout in 7 (cas v3 uses a different query parameters, etc) Detailshttps://github.com/simplesamlphp/simplesamlphp-module-casserver/blob/21418f7efbea8c4f078fd4a7d1b9eacf94dd4941/src/Controller/LogoutController.php#L104 Previous module checked the url against the valid service urls. PoCThe docker instructions from the README.md run an image with a vulnerable config. Accessing https://localhost/cas/logout?url=https://google.com will redirect to Google ImpactImpacted configs have
and are most impacted if they also have
Affected versions
v7.0.0-rc1
v7.0.0-rc2
v7.0.0-rc3
v6.0.0
v6.1.0
v6.1.1
v6.1.2
v6.2.0
v6.2.1
v6.3.0
Fixed in
6.3.1
7.0.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v7.0.0-rc1
pre
2 CVEs
CVE-2026-46491
GHSA-jrrg-99xh-5j2q
May 15, 2026
SimpleSAMLphp casserver FileSystemTicketStore path traversal allows out-of-ticket-directory read/unserialize and conditional deletion
8.6
/ 10
High
Network
Low
None
None
Unchanged
Low
High
Low
Summary
In deployments using PreconditionsThe demonstrated issue requires:
The attacker does not need administrator access to SimpleSAMLphp. ImpactAffected deployments can allow remote attackers to escape the configured CAS ticket directory through public ticket validation inputs. Confirmed impact:
The file deletion impact depends on filesystem permissions of the PHP process. In realistic deployments, this can destroy CAS tickets, serialized SimpleSAMLphp runtime/cache files, or other writable files whose contents can be unserialized into a value accepted by the The Affected versions
v6.0.0
v6.1.0
v6.1.1
v6.1.2
v6.2.0
v6.2.1
v6.3.0
v6.3.1
v7.0.0
v7.0.0-rc1
v7.0.0-rc2
v7.0.0-rc3
+ 2 more Show less
v7.0.1
v7.0.2
Fixed in
7.0.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-65954
GHSA-cvrm-5hp6-h523
May 15, 2026
SimpleSAMLphp casserver: Open Redirect in logout
4.7
/ 10
Medium
Network
Low
None
Required
Changed
None
Low
None
SummaryThe logout endpoint accepts a There are a number of other things broken with logout in 7 (cas v3 uses a different query parameters, etc) Detailshttps://github.com/simplesamlphp/simplesamlphp-module-casserver/blob/21418f7efbea8c4f078fd4a7d1b9eacf94dd4941/src/Controller/LogoutController.php#L104 Previous module checked the url against the valid service urls. PoCThe docker instructions from the README.md run an image with a vulnerable config. Accessing https://localhost/cas/logout?url=https://google.com will redirect to Google ImpactImpacted configs have
and are most impacted if they also have
Affected versions
v7.0.0-rc1
v7.0.0-rc2
v7.0.0-rc3
v6.0.0
v6.1.0
v6.1.1
v6.1.2
v6.2.0
v6.2.1
v6.3.0
Fixed in
6.3.1
7.0.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v6.2.0
minor
2 CVEs
CVE-2026-46491
GHSA-jrrg-99xh-5j2q
May 15, 2026
SimpleSAMLphp casserver FileSystemTicketStore path traversal allows out-of-ticket-directory read/unserialize and conditional deletion
8.6
/ 10
High
Network
Low
None
None
Unchanged
Low
High
Low
Summary
In deployments using PreconditionsThe demonstrated issue requires:
The attacker does not need administrator access to SimpleSAMLphp. ImpactAffected deployments can allow remote attackers to escape the configured CAS ticket directory through public ticket validation inputs. Confirmed impact:
The file deletion impact depends on filesystem permissions of the PHP process. In realistic deployments, this can destroy CAS tickets, serialized SimpleSAMLphp runtime/cache files, or other writable files whose contents can be unserialized into a value accepted by the The Affected versions
v6.0.0
v6.1.0
v6.1.1
v6.1.2
v6.2.0
v6.2.1
v6.3.0
v6.3.1
v7.0.0
v7.0.0-rc1
v7.0.0-rc2
v7.0.0-rc3
+ 2 more Show less
v7.0.1
v7.0.2
Fixed in
7.0.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-65954
GHSA-cvrm-5hp6-h523
May 15, 2026
SimpleSAMLphp casserver: Open Redirect in logout
4.7
/ 10
Medium
Network
Low
None
Required
Changed
None
Low
None
SummaryThe logout endpoint accepts a There are a number of other things broken with logout in 7 (cas v3 uses a different query parameters, etc) Detailshttps://github.com/simplesamlphp/simplesamlphp-module-casserver/blob/21418f7efbea8c4f078fd4a7d1b9eacf94dd4941/src/Controller/LogoutController.php#L104 Previous module checked the url against the valid service urls. PoCThe docker instructions from the README.md run an image with a vulnerable config. Accessing https://localhost/cas/logout?url=https://google.com will redirect to Google ImpactImpacted configs have
and are most impacted if they also have
Affected versions
v7.0.0-rc1
v7.0.0-rc2
v7.0.0-rc3
v6.0.0
v6.1.0
v6.1.1
v6.1.2
v6.2.0
v6.2.1
v6.3.0
Fixed in
6.3.1
7.0.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v6.1.2
patch
2 CVEs
CVE-2026-46491
GHSA-jrrg-99xh-5j2q
May 15, 2026
SimpleSAMLphp casserver FileSystemTicketStore path traversal allows out-of-ticket-directory read/unserialize and conditional deletion
8.6
/ 10
High
Network
Low
None
None
Unchanged
Low
High
Low
Summary
In deployments using PreconditionsThe demonstrated issue requires:
The attacker does not need administrator access to SimpleSAMLphp. ImpactAffected deployments can allow remote attackers to escape the configured CAS ticket directory through public ticket validation inputs. Confirmed impact:
The file deletion impact depends on filesystem permissions of the PHP process. In realistic deployments, this can destroy CAS tickets, serialized SimpleSAMLphp runtime/cache files, or other writable files whose contents can be unserialized into a value accepted by the The Affected versions
v6.0.0
v6.1.0
v6.1.1
v6.1.2
v6.2.0
v6.2.1
v6.3.0
v6.3.1
v7.0.0
v7.0.0-rc1
v7.0.0-rc2
v7.0.0-rc3
+ 2 more Show less
v7.0.1
v7.0.2
Fixed in
7.0.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-65954
GHSA-cvrm-5hp6-h523
May 15, 2026
SimpleSAMLphp casserver: Open Redirect in logout
4.7
/ 10
Medium
Network
Low
None
Required
Changed
None
Low
None
SummaryThe logout endpoint accepts a There are a number of other things broken with logout in 7 (cas v3 uses a different query parameters, etc) Detailshttps://github.com/simplesamlphp/simplesamlphp-module-casserver/blob/21418f7efbea8c4f078fd4a7d1b9eacf94dd4941/src/Controller/LogoutController.php#L104 Previous module checked the url against the valid service urls. PoCThe docker instructions from the README.md run an image with a vulnerable config. Accessing https://localhost/cas/logout?url=https://google.com will redirect to Google ImpactImpacted configs have
and are most impacted if they also have
Affected versions
v7.0.0-rc1
v7.0.0-rc2
v7.0.0-rc3
v6.0.0
v6.1.0
v6.1.1
v6.1.2
v6.2.0
v6.2.1
v6.3.0
Fixed in
6.3.1
7.0.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v6.1.1
patch
2 CVEs
CVE-2026-46491
GHSA-jrrg-99xh-5j2q
May 15, 2026
SimpleSAMLphp casserver FileSystemTicketStore path traversal allows out-of-ticket-directory read/unserialize and conditional deletion
8.6
/ 10
High
Network
Low
None
None
Unchanged
Low
High
Low
Summary
In deployments using PreconditionsThe demonstrated issue requires:
The attacker does not need administrator access to SimpleSAMLphp. ImpactAffected deployments can allow remote attackers to escape the configured CAS ticket directory through public ticket validation inputs. Confirmed impact:
The file deletion impact depends on filesystem permissions of the PHP process. In realistic deployments, this can destroy CAS tickets, serialized SimpleSAMLphp runtime/cache files, or other writable files whose contents can be unserialized into a value accepted by the The Affected versions
v6.0.0
v6.1.0
v6.1.1
v6.1.2
v6.2.0
v6.2.1
v6.3.0
v6.3.1
v7.0.0
v7.0.0-rc1
v7.0.0-rc2
v7.0.0-rc3
+ 2 more Show less
v7.0.1
v7.0.2
Fixed in
7.0.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-65954
GHSA-cvrm-5hp6-h523
May 15, 2026
SimpleSAMLphp casserver: Open Redirect in logout
4.7
/ 10
Medium
Network
Low
None
Required
Changed
None
Low
None
SummaryThe logout endpoint accepts a There are a number of other things broken with logout in 7 (cas v3 uses a different query parameters, etc) Detailshttps://github.com/simplesamlphp/simplesamlphp-module-casserver/blob/21418f7efbea8c4f078fd4a7d1b9eacf94dd4941/src/Controller/LogoutController.php#L104 Previous module checked the url against the valid service urls. PoCThe docker instructions from the README.md run an image with a vulnerable config. Accessing https://localhost/cas/logout?url=https://google.com will redirect to Google ImpactImpacted configs have
and are most impacted if they also have
Affected versions
v7.0.0-rc1
v7.0.0-rc2
v7.0.0-rc3
v6.0.0
v6.1.0
v6.1.1
v6.1.2
v6.2.0
v6.2.1
v6.3.0
Fixed in
6.3.1
7.0.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v6.1.0
minor
2 CVEs
CVE-2026-46491
GHSA-jrrg-99xh-5j2q
May 15, 2026
SimpleSAMLphp casserver FileSystemTicketStore path traversal allows out-of-ticket-directory read/unserialize and conditional deletion
8.6
/ 10
High
Network
Low
None
None
Unchanged
Low
High
Low
Summary
In deployments using PreconditionsThe demonstrated issue requires:
The attacker does not need administrator access to SimpleSAMLphp. ImpactAffected deployments can allow remote attackers to escape the configured CAS ticket directory through public ticket validation inputs. Confirmed impact:
The file deletion impact depends on filesystem permissions of the PHP process. In realistic deployments, this can destroy CAS tickets, serialized SimpleSAMLphp runtime/cache files, or other writable files whose contents can be unserialized into a value accepted by the The Affected versions
v6.0.0
v6.1.0
v6.1.1
v6.1.2
v6.2.0
v6.2.1
v6.3.0
v6.3.1
v7.0.0
v7.0.0-rc1
v7.0.0-rc2
v7.0.0-rc3
+ 2 more Show less
v7.0.1
v7.0.2
Fixed in
7.0.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-65954
GHSA-cvrm-5hp6-h523
May 15, 2026
SimpleSAMLphp casserver: Open Redirect in logout
4.7
/ 10
Medium
Network
Low
None
Required
Changed
None
Low
None
SummaryThe logout endpoint accepts a There are a number of other things broken with logout in 7 (cas v3 uses a different query parameters, etc) Detailshttps://github.com/simplesamlphp/simplesamlphp-module-casserver/blob/21418f7efbea8c4f078fd4a7d1b9eacf94dd4941/src/Controller/LogoutController.php#L104 Previous module checked the url against the valid service urls. PoCThe docker instructions from the README.md run an image with a vulnerable config. Accessing https://localhost/cas/logout?url=https://google.com will redirect to Google ImpactImpacted configs have
and are most impacted if they also have
Affected versions
v7.0.0-rc1
v7.0.0-rc2
v7.0.0-rc3
v6.0.0
v6.1.0
v6.1.1
v6.1.2
v6.2.0
v6.2.1
v6.3.0
Fixed in
6.3.1
7.0.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v6.0.0
initial
2 CVEs
CVE-2026-46491
GHSA-jrrg-99xh-5j2q
May 15, 2026
SimpleSAMLphp casserver FileSystemTicketStore path traversal allows out-of-ticket-directory read/unserialize and conditional deletion
8.6
/ 10
High
Network
Low
None
None
Unchanged
Low
High
Low
Summary
In deployments using PreconditionsThe demonstrated issue requires:
The attacker does not need administrator access to SimpleSAMLphp. ImpactAffected deployments can allow remote attackers to escape the configured CAS ticket directory through public ticket validation inputs. Confirmed impact:
The file deletion impact depends on filesystem permissions of the PHP process. In realistic deployments, this can destroy CAS tickets, serialized SimpleSAMLphp runtime/cache files, or other writable files whose contents can be unserialized into a value accepted by the The Affected versions
v6.0.0
v6.1.0
v6.1.1
v6.1.2
v6.2.0
v6.2.1
v6.3.0
v6.3.1
v7.0.0
v7.0.0-rc1
v7.0.0-rc2
v7.0.0-rc3
+ 2 more Show less
v7.0.1
v7.0.2
Fixed in
7.0.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-65954
GHSA-cvrm-5hp6-h523
May 15, 2026
SimpleSAMLphp casserver: Open Redirect in logout
4.7
/ 10
Medium
Network
Low
None
Required
Changed
None
Low
None
SummaryThe logout endpoint accepts a There are a number of other things broken with logout in 7 (cas v3 uses a different query parameters, etc) Detailshttps://github.com/simplesamlphp/simplesamlphp-module-casserver/blob/21418f7efbea8c4f078fd4a7d1b9eacf94dd4941/src/Controller/LogoutController.php#L104 Previous module checked the url against the valid service urls. PoCThe docker instructions from the README.md run an image with a vulnerable config. Accessing https://localhost/cas/logout?url=https://google.com will redirect to Google ImpactImpacted configs have
and are most impacted if they also have
Affected versions
v7.0.0-rc1
v7.0.0-rc2
v7.0.0-rc3
v6.0.0
v6.1.0
v6.1.1
v6.1.2
v6.2.0
v6.2.1
v6.3.0
Fixed in
6.3.1
7.0.0
References
Updated Sep 10, 2026 · Source: OSV.dev |