CVE-2026-15615
N/A
N/A
Summary
Logto omits validation of the SAML <Conditions> element, enabling attackers to strip time and audience restrictions and replay assertions indefinitely.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Logto | Logto | 1.12.0 <= 1.37.1 | affected |
Weaknesses
- CWE-345 Insufficient Verification of Data Authenticity
References
- https://github.com/logto-io/logto/blob/ea3ede35028dfd0bbb6d7b239623ce0e7f6cdff8/packages/core/src/sso/SamlConnector/utils.ts#L175-L205
- https://github.com/logto-io/logto/blob/ea3ede35028dfd0bbb6d7b239623ce0e7f6cdff8/packages/connectors/connector-saml/src/utils.ts#L46-L110
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.