CVE-2026-89043High· 7.4▾ MidnightPoC availablepassport-saml-encrypted through 0.1.13 contains an XML signature wrapping vulnerability where signature verification and assertion extraction use independent XPath lookups with no cross-validation. Attackers holding any validly signed SA…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 40.7 · likelihood 0.1 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake. The CVSS score shown above comes from the assigning CNA record, not NVD.
Exploit-prediction probability, daily snapshots since Sep 11.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CVEORG
0.3%
passport-saml-encrypted through 0.1.13 contains an XML signature wrapping vulnerability where signature verification and assertion extraction use independent XPath lookups with no cross-validation. Attackers holding any validly signed SAML message can prepend a forged unsigned assertion that gets accepted as the verified identity while the genuine signature validates against the original assertion.
passport-saml-encrypted <= 0.1.13Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-89042Critical· 9.1passport-saml-encrypted through 0.1.13 Authentication Bypass via Missing Signature Verification
CVE-2026-1529High· 8.1A flaw was found in Keycloak
CVE-2026-59163Critical· 9.1Mnemosyne is a memory layer for artificial intelligence agents
CVE-2026-86038High· 7.5libp2p is a JavaScript implementation of the libp2p networking stack
CVE-2026-92718High· 7.3Nuclei versions before 3.11.1 cache template signature verification based only on file modification time without content checksums
CVE-2026-89086Critical· 9.1In the jose package before 0.11.0 for OCaml, library calls to validate an RSA signature only confirm that PKCS #1 decoding succeeds, and proceed to declare the signature valid without the required steps that involve the public key.