passport-saml-encrypted vulnerabilities
CVEs whose affected-version data names the passport-saml-encrypted package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-89042Critical· 9.1passport-saml-encrypted through 0.1.13 Authentication Bypass via Missing Signature Verification
passport-saml-encrypted through 0.1.13 makes SAML signature verification conditional on an optional cert option, allowing attackers to bypass authentication by submitting unsigned SAML responses. Attackers can post forged SAML responses …
▾ Midnightkrakenjs · passport-saml-encryptedEPSS 0.27%via CVEORG
CVE-2026-89043High· 7.4PoCpassport-saml-encrypted through 0.1.13 XML Signature Wrapping via Assertion Prepending
passport-saml-encrypted through 0.1.13 contains an XML signature wrapping vulnerability where signature verification and assertion extraction use independent XPath lookups with no cross-validation. Attackers holding any validly signed SA…
▾ Midnightkrakenjs · passport-saml-encryptedEPSS 0.28%via CVEORG