Skip to content

Conversation

@zendesk-mradmacher
Copy link

@zendesk-mradmacher zendesk-mradmacher commented Oct 24, 2025

Fixes SAML signature wrapping vulnerability

Ensures that a Response or an Assertion is considered signed only if the signature enveloped inside references that element.

@zendesk-mradmacher zendesk-mradmacher force-pushed the mradmacher/signature-wrapping-attack-fix branch from 5379215 to 9f70c39 Compare October 30, 2025 13:58
@zendesk-mradmacher zendesk-mradmacher force-pushed the mradmacher/signature-wrapping-attack-fix branch from 9f70c39 to 6210a87 Compare October 30, 2025 14:19
@zendesk-mradmacher zendesk-mradmacher requested review from a team and zkhendrix and removed request for a team October 30, 2025 14:20
@zendesk-mradmacher zendesk-mradmacher marked this pull request as ready for review October 30, 2025 14:22
@zendesk-mradmacher zendesk-mradmacher requested review from a team and removed request for zkhendrix October 30, 2025 14:22
@zendesk-mradmacher zendesk-mradmacher changed the title add tests to prove signature wrapping attack resistance Fix SAML Signature Wrapping Vulnerability Oct 30, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants