Skip to content

4.7.1

Choose a tag to compare

@william-suppo william-suppo released this 10 Sep 07:20
· 17 commits to master since this release

Security

  • Reject XML Signature Wrapping (XSW) attacks in SignatureXmlReader (#122)

Backport to the 4.x line of the fix released in 5.0.1 (#113), for consumers
pinned to litesaml/lightsaml: ^4.0 that cannot adopt the 5.0.0 breaking
changes.

LightSAML 4.x was vulnerable to an XML Signature Wrapping (XSW) attack
(GHSA-w553-pwx6-3mg9 / CVE-2026-63182) allowing an attacker who has captured
one genuine signed assertion to have LightSAML accept a fully attacker-authored
assertion as IdP-signed, leading to authentication bypass and privilege
escalation.

The fix enforces two invariants before signature validation: the ds:Signature
parent element must carry the ID referenced by the fragment URI, and that ID
must be unique in the document.

Full Changelog: 4.7.0...4.7.1