samly
Hex2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting samlypage 1 of 1
- CVE-2026-53424CRITICALCVSS 9.1EG 9.12026-08-20
vulnerable: 0.10.0 ... 1.4.0 (27 versions)
Authentication Bypass by Capture-replay vulnerability in dropbox samly allows an attacker to authenticate as the subject of a captured SAML assertion by resubmitting it. Samly.Helper.decode_idp_auth_resp/3 in lib/samly/helper.ex calls esa…
- CVE-2026-53425HIGHCVSS 7.6EG 7.62026-08-20
vulnerable: 0.10.0 ... 1.4.0 (27 versions)
Insufficient Verification of Data Authenticity vulnerability in dropbox samly allows an attacker to establish an authenticated session using a SAML response the service provider never requested. Samly.SPHandler.validate_authresp/3 in lib/…
Check whether samly is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for samly CVEs against the assets you own.
Start Free Scan →