Improper Verification of Cryptographic Signature in gosaml2 - #VU144267

 

Improper Verification of Cryptographic Signature in gosaml2 - #VU144267

Published: August 19, 2026


Vulnerability identifier: #VU144267
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-347
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to forge SAML LogoutResponse messages.

The vulnerability exists due to improper verification of cryptographic signature in ValidateEncodedLogoutResponsePOST when processing a LogoutResponse with no XML signature. A remote attacker can send a specially crafted unsigned LogoutResponse to forge SAML LogoutResponse messages.

This can be used to confirm session termination that did not occur, inject arbitrary status codes and session indexes, or disrupt the single logout flow between the service provider and identity provider.


Affected software

gosaml2

Remediation

Install security update from vendor's website.

gosaml2 - update to 0.12.0

External References

Related Security Bulletins