USN-8770-1: SimpleSAMLphp vulnerabilities
It was discovered that SimpleSAMLphp incorrectly validated cryptographic signatures in XML messages. An authenticated attacker could possibly use this issue to impersonate users or gain elevated privileges. This issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2019-3465) It was discovered that SimpleSAMLphp incorrectly handled external entities when parsing untrusted XML documents. A remote attacker could possibly use this issue to obtain sensitive information. This issue did not affect Ubuntu 24.04 LTS. (CVE-2024-52596) It was discovered that SimpleSAMLphp incorrectly verified signatures in SAML messages using the HTTP-Redirect binding. A remote attacker could possibly use this issue to bypass authentication and impersonate users. (CVE-2025-27773)
Details
Original advisory: https://ubuntu.com/security/notices/USN-8770-1
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Moderate exploitation riskCVE-2019-34653.0% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 87% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2024-525960.98% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 60% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2025-277730.39% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 32% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2019-3465 | coverage & exploitation status | NVD · CVE.org |
| CVE-2024-52596 | coverage & exploitation status | NVD · CVE.org |
| CVE-2025-27773 | coverage & exploitation status | NVD · CVE.org |
More from Ubuntu Security Notices
- unknownUSN-8769-1: phpseclib vulnerability2026-09-15
- unknownUSN-8768-1: Shibboleth vulnerability2026-09-15
- unknownUSN-8767-1: Snapcast vulnerability2026-09-15
- unknownUSN-8766-1: Suricata-Update vulnerability2026-09-15
- unknownUSN-8765-1: python-sql vulnerability2026-09-15