pysaml2 vulnerabilities
CVEs whose affected-version data names the pysaml2 package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2021-21238Medium· 6.5SAML XML Signature wrapping in PySAML2
SAML XML Signature wrapping in PySAML2
▾ Sunlitpysaml2 · pysaml2EPSS 1.1%via OSV
CVE-2021-21239Medium· 6.5PoCImproper Verification of Cryptographic Signature in PySAML2
Improper Verification of Cryptographic Signature in PySAML2
▾ Twilightpysaml2 · pysaml2EPSS 1.3%via OSV