Repository navigation
4.7.1
Security
- Reject XML Signature Wrapping (XSW) attacks in SignatureXmlReader (#122)
Backport to the 4.x line of the fix released in 5.0.1 (#113), for consumers
pinned to litesaml/lightsaml: ^4.0 that cannot adopt the 5.0.0 breaking
changes.
LightSAML 4.x was vulnerable to an XML Signature Wrapping (XSW) attack
(GHSA-w553-pwx6-3mg9 / CVE-2026-63182) allowing an attacker who has captured
one genuine signed assertion to have LightSAML accept a fully attacker-authored
assertion as IdP-signed, leading to authentication bypass and privilege
escalation.
The fix enforces two invariants before signature validation: the ds:Signature
parent element must carry the ID referenced by the fragment URI, and that ID
must be unique in the document.
Full Changelog: 4.7.0...4.7.1