[Git][security-tracker-team/security-tracker][master] Update status on CVE-2026-49284/simplesamlphp
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Mon Jul 27 05:45:15 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
9eacea0c by Salvatore Bonaccorso at 2026-07-27T06:44:49+02:00
Update status on CVE-2026-49284/simplesamlphp
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -10266,7 +10266,7 @@ CVE-2026-49834 (sigstore-go is a Go library for Sigstore signing and verificatio
CVE-2026-49485 (HAPI FHIR is a complete implementation of the HL7 FHIR standard for he ...)
NOT-FOR-US: HAPI FHIR
CVE-2026-49284 (SimpleSAMLphp versions before 1.18.6 contain an information disclosure ...)
- - simplesamlphp <unfixed>
+ - simplesamlphp 2.4.8-1
[bookworm] - simplesamlphp <postponed> (Reachability-gated: multi-IdP mixed-trust deployments only; SP warns-and-continues on issuer mismatch and accepts unsigned Response InResponseTo; fix along with the next DLA)
[bullseye] - simplesamlphp <postponed> (Reachability-gated: multi-IdP mixed-trust deployments only; SP warns-and-continues on issuer mismatch and accepts unsigned Response InResponseTo; fix along with the next DLA)
NOTE: https://github.com/simplesamlphp/simplesamlphp/security/advisories/GHSA-q8r6-xj3f-wrrm
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9eacea0c863bedcadb6ccabd42baf28813700d9d
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9eacea0c863bedcadb6ccabd42baf28813700d9d
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260727/1beefe03/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list