Improper Verification of Cryptographic Signature in gosaml2 - #VU128391
Published: April 28, 2026
gosaml2
Russell Haering
Description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper verification of cryptographic signature in ValidateEncodedLogoutRequestPOST when processing SAML LogoutRequest messages sent to the single logout endpoint. A remote attacker can send a specially crafted unsigned logout request to cause a denial of service.
Unsigned requests may be accepted even when signature validation is configured to be enforced.