---
id: CVE-2025-65954
title: >-
  SimpleSAMLphp-casserver is a CAS 1.0 and 2.0 compliant CAS server in the form
  of a SimpleSAMLphp module
summary: >-
  SimpleSAMLphp-casserver is a CAS 1.0 and 2.0 compliant CAS server in the form
  of a SimpleSAMLphp module. In versions below 6.3.1 and 7.0.0, the logout
  endpoint accepts a url query parameter to redirect to. casserver treats that
  url as tr…
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-601
vendor: simplesamlphp
product: simplesamlphp-module-casserver
affected:
  - simplesamlphp-module-casserver < 6.3.1
  - simplesamlphp-module-casserver = 7.0.0
patched:
  - simplesamlphp-module-casserver 6.3.1
published: '2026-05-18'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T21:10:00.190'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-65954'
references:
  - url: >-
      https://github.com/simplesamlphp/simplesamlphp-module-casserver/commit/0462f50f00b3bb300d83067d11b74146a57bb8e0
    label: security-advisories@github.com
  - url: >-
      https://github.com/simplesamlphp/simplesamlphp-module-casserver/commit/fb6c6f1c7b9e757c93c5c306e1d36405e64f6dc5
    label: security-advisories@github.com
  - url: >-
      https://github.com/simplesamlphp/simplesamlphp-module-casserver/security/advisories/GHSA-cvrm-5hp6-h523
    label: security-advisories@github.com
  - url: >-
      https://github.com/simplesamlphp/simplesamlphp-module-casserver/security/advisories/GHSA-cvrm-5hp6-h523
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00269
epssPercentile: 0.17204
ingestedAt: '2026-09-30T21:25:07.731Z'
---

## Overview

SimpleSAMLphp-casserver is a CAS 1.0 and 2.0 compliant CAS server in the form of a SimpleSAMLphp module. In versions below 6.3.1 and 7.0.0, the logout endpoint accepts a url query parameter to redirect to. casserver treats that url as trusted, and either (depending on configuration) redirects the browser there, or shows a "you've been logged out" page with a link to continue to that url. Impacted configs include 'enable_logout' => true, and 'skip_logout_page' -> true. This issue has been resolved in versions 6.3.1 and 7.0.0.

## Affected

- `simplesamlphp-module-casserver < 6.3.1`
- `simplesamlphp-module-casserver = 7.0.0`

## Remediation

Upgrade past the affected range:

- `simplesamlphp-module-casserver 6.3.1`
