SCA: security update for simplesamlphp/saml2, simplesamlphp/saml2-legacy (GHSA-5cjr-mxj5-wmrx)

high Tenable Cloud Security Plugin ID 445690

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. In 4.19.2 and 4.20.2,
the library permits attacker-controlled XPath transforms while processing XML signatures in specially
crafted SAML messages. XPath evaluation can consume uncontrolled processing resources, allowing a remote
unauthenticated attacker to deny service to any entity relying on SimpleSAMLphp or directly on the SAML2
library. The mitigation limits the number of transforms, permits only transform algorithms identified by
the SAML 2.0 Core specification, and specifically rejects XPath transforms. This issue is fixed in
versions 4.19.3 and 4.20.3. (CVE-2026-49289)

Solution

Update the simplesamlphp/saml2 library and its related packages to version 4.19.3 or later.

See Also

https://github.com/advisories/GHSA-5cjr-mxj5-wmrx

Plugin Details

Severity: High

ID: 445690

Version: Revision 1.2

Type: Local

Family: SCA Checks

Published: 8/5/2026

Updated: 8/20/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.66

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 5.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS Score Source: CVE-2026-49289

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 7/2/2026

Vulnerability Publication Date: 7/2/2026

Reference Information

CVE: CVE-2026-49289

cwe: CWE-400