{"id":"GHSA-5j8p-438x-rgg5","summary":" SAML PHP Toolkit Vulnerability on xmlseclibs CVE-2025-66475 ","details":"**Summary**\n\nThere is a critical vulnerability on xmlseclibs [CVE-2025-66475](https://github.com/robrichards/xmlseclibs/security/advisories/GHSA-c4cc-x928-vjw9), a dependency of php-saml\n\nUpdate to the following versions of php-saml which forces the use of patched versions of xmlseclibs:\n- [2.21.1](https://github.com/SAML-Toolkits/php-saml/releases/tag/2.21.1)\n- [3.8.1](https://github.com/SAML-Toolkits/php-saml/releases/tag/3.8.1)\n- [4.3.1](https://github.com/SAML-Toolkits/php-saml/releases/tag/4.3.1)\n\n\n**Impact**\n\nSignature Wrapping Vulnerabilities allows an attacker to impersonate a user.","modified":"2025-12-09T17:51:17.350635Z","published":"2025-12-09T17:24:09Z","database_specific":{"cwe_ids":["CWE-1395"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2025-12-09T17:24:09Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/SAML-Toolkits/php-saml/security/advisories/GHSA-5j8p-438x-rgg5"},{"type":"WEB","url":"https://github.com/robrichards/xmlseclibs/security/advisories/GHSA-c4cc-x928-vjw9"},{"type":"PACKAGE","url":"https://github.com/SAML-Toolkits/php-saml"},{"type":"WEB","url":"https://github.com/SAML-Toolkits/php-saml/releases/tag/2.21.1"},{"type":"WEB","url":"https://github.com/SAML-Toolkits/php-saml/releases/tag/3.8.1"},{"type":"WEB","url":"https://github.com/SAML-Toolkits/php-saml/releases/tag/4.3.1"}],"affected":[{"package":{"name":"onelogin/php-saml","ecosystem":"Packagist","purl":"pkg:composer/onelogin/php-saml"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.21.1"}]}],"versions":["2.0.0","2.1.0","2.10.0","2.10.1","2.10.2","2.10.3","2.10.4","2.10.5","2.10.6","2.10.7","2.11.0","2.16.0","2.17.0","2.17.1","2.18.0","2.18.1","2.19.0","2.19.1","2.20.0","2.21.0","2.3.0","2.4.0","2.5.0","2.6.0","2.6.1","2.7.0","2.8.0","2.9.0","2.9.1","v2.12.0","v2.13.0","v2.14.0","v2.15.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/12/GHSA-5j8p-438x-rgg5/GHSA-5j8p-438x-rgg5.json"}},{"package":{"name":"onelogin/php-saml","ecosystem":"Packagist","purl":"pkg:composer/onelogin/php-saml"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.0.0"},{"fixed":"3.8.1"}]}],"versions":["3.1.1","3.2.0","3.2.1","3.3.0","3.3.1","3.4.0","3.4.1","3.5.0","3.5.1","3.6.0","3.6.1","3.7.0","3.8.0","v3.0.0","v3.1.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/12/GHSA-5j8p-438x-rgg5/GHSA-5j8p-438x-rgg5.json"}},{"package":{"name":"onelogin/php-saml","ecosystem":"Packagist","purl":"pkg:composer/onelogin/php-saml"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.0.0"},{"fixed":"4.3.1"}]}],"versions":["4.0.0","4.0.1","4.1.0","4.2.0","4.3.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/12/GHSA-5j8p-438x-rgg5/GHSA-5j8p-438x-rgg5.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"}]}