Home / mailingsPDF  

[USN-8770-1] SimpleSAMLphp vulnerabilities

Posted on 15 September 2026
Ubuntu Security

==========================================================================Ubuntu Security Notice USN-8770-1
September 15, 2026

simplesamlphp vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS

Summary:

Several security issues were fixed in SimpleSAMLphp.

Software Description:
- simplesamlphp: Authentication and federation application supporting several protocols

Details:

It was discovered that SimpleSAMLphp incorrectly validated cryptographic
signatures in XML messages. An authenticated attacker could possibly use
this issue to impersonate users or gain elevated privileges. This issue
only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2019-3465)

It was discovered that SimpleSAMLphp incorrectly handled external entities
when parsing untrusted XML documents. A remote attacker could possibly use
this issue to obtain sensitive information. This issue did not affect
Ubuntu 24.04 LTS. (CVE-2024-52596)

It was discovered that SimpleSAMLphp incorrectly verified signatures in
SAML messages using the HTTP-Redirect binding. A remote attacker could
possibly use this issue to bypass authentication and impersonate users.
(CVE-2025-27773)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 24.04 LTS
simplesamlphp 1.19.7-1+deb12u1ubuntu0.1

Ubuntu 22.04 LTS
simplesamlphp 1.19.1-1.1ubuntu0.1~esm1
Available with Ubuntu Pro

Ubuntu 20.04 LTS
simplesamlphp 1.18.4-1ubuntu0.1~esm1
Available with Ubuntu Pro

Ubuntu 18.04 LTS
simplesamlphp 1.15.3-1ubuntu0.1~esm1
Available with Ubuntu Pro

Ubuntu 16.04 LTS
simplesamlphp 1.14.0-1ubuntu2+esm1
Available with Ubuntu Pro

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-8770-1
CVE-2019-3465, CVE-2024-52596, CVE-2025-27773

Package Information:
https://launchpad.net/ubuntu/+source/simplesamlphp/1.19.7-1+deb12u1ubuntu0.1

--===============4203343182107077029==Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature

 

TOP