Back to Database
Status published
High
CVE-2024-52596
SimpleSAMLphp xml-common XXE vulnerability
Vulnerability Description
SimpleSAMLphp xml-common is a common classes for handling XML-structures. When loading an (untrusted) XML document, for example the SAMLResponse, it's possible to induce an XXE. This vulnerability is fixed in 1.19.0.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-52596
Credits & Attribution
No credits recorded in the NVD database.
References
More from simplesamlphp
View All →CVE-2025-65954
SimpleSAMLphp-casserver has an Open Redirect vulnerability via logout
Medium
4.7
CVE-2025-27773
SimpleSAMLphp SAML2 library has incorrect signature verification for HTTP-Redirect binding
High
8.6
CVE-2024-52806
SimpleSAMLphp SAML2 has an XXE in parsing SAML messages
High
8.3
CVE-2023-49087
Validation of SignedInfo
Medium
6.8
CVE-2020-5301
Information disclosure of source code in SimpleSAMLphp
Low
3
Affected Vendor
simplesamlphp
View all reports →Affected Software
xml-common
Vulnerable Versions:
< 1.20.0
Timeline
Official Publish:
December 2nd, 2024
Last Modified:
December 2nd, 2024
Added to House:
July 22nd, 2026