{"id":"GHSA-5j8p-438x-rgg5","aliases":[],"url":"https://o3.security/vulnerability/GHSA-5j8p-438x-rgg5","summary":" SAML PHP Toolkit Vulnerability on xmlseclibs CVE-2025-66475 ","details":"**Summary**\n\nThere is a critical vulnerability on xmlseclibs [CVE-2025-66475](https://github.com/robrichards/xmlseclibs/security/advisories/GHSA-c4cc-x928-vjw9), a dependency of php-saml\n\nUpdate to the following versions of php-saml which forces the use of patched versions of xmlseclibs:\n- [2.21.1](https://github.com/SAML-Toolkits/php-saml/releases/tag/2.21.1)\n- [3.8.1](https://github.com/SAML-Toolkits/php-saml/releases/tag/3.8.1)\n- [4.3.1](https://github.com/SAML-Toolkits/php-saml/releases/tag/4.3.1)\n\n\n**Impact**\n\nSignature Wrapping Vulnerabilities allows an attacker to impersonate a user.","published":"2025-12-09T17:24:09Z","modified":"2025-12-09T17:51:17.350635Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"onelogin/php-saml","fixedVersion":"2.21.1"},{"ecosystem":"Packagist","name":"onelogin/php-saml","fixedVersion":"3.8.1"},{"ecosystem":"Packagist","name":"onelogin/php-saml","fixedVersion":"4.3.1"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/SAML-Toolkits/php-saml/security/advisories/GHSA-5j8p-438x-rgg5"},{"type":"WEB","url":"https://github.com/robrichards/xmlseclibs/security/advisories/GHSA-c4cc-x928-vjw9"},{"type":"PACKAGE","url":"https://github.com/SAML-Toolkits/php-saml"},{"type":"WEB","url":"https://github.com/SAML-Toolkits/php-saml/releases/tag/2.21.1"},{"type":"WEB","url":"https://github.com/SAML-Toolkits/php-saml/releases/tag/3.8.1"},{"type":"WEB","url":"https://github.com/SAML-Toolkits/php-saml/releases/tag/4.3.1"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2025-12-09T17:51:17.350635Z"}}