Improper Verification of Cryptographic Signature in gosaml2 - #VU144267
Published: August 19, 2026
Vulnerability details
The vulnerability allows a remote attacker to forge SAML LogoutResponse messages.
The vulnerability exists due to improper verification of cryptographic signature in ValidateEncodedLogoutResponsePOST when processing a LogoutResponse with no XML signature. A remote attacker can send a specially crafted unsigned LogoutResponse to forge SAML LogoutResponse messages.
This can be used to confirm session termination that did not occur, inject arbitrary status codes and session indexes, or disrupt the single logout flow between the service provider and identity provider.