Zum Inhalt springen.
Sympa Menü

it-securitynotifies - [IT-SecNots] [Security-news] SAML SSO - Service Provider - Critical - Weak cryptographic practices - SA-CONTRIB-2026-144

it-securitynotifies AT lists.piratenpartei.de

Betreff: Sicherheitsankündigungen

Listenarchiv

[IT-SecNots] [Security-news] SAML SSO - Service Provider - Critical - Weak cryptographic practices - SA-CONTRIB-2026-144


Chronologisch Thread  
  • From: security-news AT drupal.org
  • To: security-news AT drupal.org
  • Subject: [IT-SecNots] [Security-news] SAML SSO - Service Provider - Critical - Weak cryptographic practices - SA-CONTRIB-2026-144
  • Date: Wed, 9 Sep 2026 17:21:02 +0000
  • Arc-authentication-results: i=2; smtp2.osuosl.org; arc=fail smtp.remote-ip=140.211.10.49
  • Arc-authentication-results: i=1; smtp1.osuosl.org; dmarc=pass header.from=drupal.org; dkim=pass header.d=drupal.org header.i= AT drupal.org header.a=rsa-sha256 header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b="XC0/FzKX"; dkim=pass header.d=amazonses.com header.i= AT amazonses.com header.a=rsa-sha256 header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=XBaKwROT; arc=none smtp.remote-ip=54.240.27.38
  • Arc-filter: OpenARC Filter v1.3.0 smtp2.osuosl.org E886040384
  • Arc-filter: OpenARC Filter v1.3.0 smtp1.osuosl.org B696D80E14
  • Arc-message-signature: i=2; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1788975610; h=X-Comment:DKIM-Signature:Received:X-Spam-Flag:X-Spam-Score: X-Spam-Level:X-Spam-Status:ARC-Filter:Received-SPF:DKIM-Signature: DKIM-Signature:Date:To:MIME-Version:Feedback-ID:X-Mailman-Rule-Hits: X-Mailman-Rule-Misses:Message-ID-Hash:X-Mailman-Approved-At: Message-ID:From:X-Mailman-Version:Precedence:Reply-To:Subject:List-Id: Archived-At:List-Archive:List-Help:List-Owner:List-Post: List-Subscribe:List-Unsubscribe:Content-Type: Content-Transfer-Encoding; bh=mt7dzHSSd/tyiofLNXBKPTp4Ta9uT318U78E86pHyZA=; b=iNctCwhATVth2hjiG9JpaNi2aMvLN3FaxWwy6aJffqMm09zkCQWaa6B0WqIJGCslK1vL BgGCMewhFyOJwTLUty562xY7Aq1qOUWWIlKSikYl3xw/C3SjfF4Eh/cUu1y2LEvCLD/kL W97czM0PfDCXKp+gIJo8f9cmiqwv767YbJAXmoYfOxG8fzVQbm4HN9ks8185WWm4UiByb 5Qf61sJvftN5H8tt71ijy8WnKJdISYPX5y/hBtlwai+73dwMQbmiT7G2x/8EM4sJbpVVd 6Rav+rN87LVdTZJ1nVTrB6LiOcykR0Zk2ULiOrSxnglHxZsEHkhI2N88EOlEIQjwbIQ==
  • Arc-message-signature: i=1; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1788974463; h=Received-SPF:DKIM-Signature:DKIM-Signature:Date:Message-ID:To: Subject:X-PHP-Originating-Script:MIME-Version:Content-Type: Content-Transfer-Encoding:X-Mailer:Sender:From:Feedback-ID: X-SES-Outgoing; bh=slO+murkKTrrY/6hZy33FH4A6ELt3Be6UvbJYZXasyo=; b=qjokSpvtO+Rv4SSlAubQmMpUPA6EWaV7byfEisUuOOLhdtIeVSDOQ4uWGrJ+jp44+UyG d4xdYlCdjOO2LQ2xfo7dLD21JMGky3hGlYHurruK9Q07rkmfeuWI9EWpbmZsn9Qgp9rPv qpIZaHr3u6tUpjpydDVYCx/7bn2/ySTZrbP+dLVHwVQhGioOwc9Piga6Qhk0EcrkPMcnn lQKzovzLKVM3XCPBjPJFnmUje1f3mpXSVJmsHMbFEfcTvJbWvmdLsB1Wbn3T2Ii0MrHic WEXJARu87Jrv++qLPZr0zdXdYOiPdJUxDeMA9jcRc9MViNqlI8FqjxBvzvRq9TIGE+Q==
  • Arc-seal: i=2; d=osuosl.org; s=arc; a=rsa-sha256; cv=fail; t=1788975610; b=i5xPlPNKB5ge5F42KqcoX6sKruZ75SkOOT4zPgkrNLqHZht8IHFMpZ205ed/5wuXMAtN g5ucyN6U1jRwvtsB0RmOMrxCQfB7lyp9KfblAzQA0/U/GvCHHu51tWE4ZoTkUXlYg+eXK r1lizs7fz+6/cV7IvQXrJxl4RN6fSFTuenu9Y64tAchIs6vxjZqO8FzbyjLuUEnkP129u AZouUPthOkWm5PNZfd49lqMpAiBeceE5Iyoo9IRPDKkgZ/NPsnmytqs30Rh0r3aF77CLc yaWgYeJIlCd9MfTCyq9E9QP264BHCwOldeYr5JMdPxtJ1RUHRKBgumIpmRX2rtYRjEg==
  • Arc-seal: i=1; d=osuosl.org; s=arc; a=rsa-sha256; cv=none; t=1788974463; b=mly/5jz1LCSY8g8Zuv2O8txcJQHEQHr3tTNwaYH+Pu+6ANU1J/6w50J+kkGs9zsSsJtf 7XkHE82oNtY4Qo03XWARL+bct0rZSSxTklhV+A0D1eK47/qyT0X9hP3D+W2upWfiQWoC2 ILR7+hL3ewiidPOknMi2cvQp1DpnEnkJ1Zm2SLvT1C5ORaD6sujrcqyTQe2pgo9WGJ9oN u2ov/0BI6QkUzJ8UaW8Os1vGvQteoWADtjxO1Q9Z7Zi4vlFOXWnx8EEOGPI7CGUVTglpt jxA08lTG0gnryvOTsVgqoO3xYLQBUGCAOwPVfKkQIQJIHmDK8UC7/1cYX+qUOSOQsUw==
  • Archived-at: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/message/NZD5BTEFEO7SXGS5GLBIH2HVLFTDE2SY/>
  • Authentication-results: lists.piratenpartei.de; dkim=pass header.d=drupal.org header.s=default header.b=OERJGCry; dkim=fail ("body hash did not verify") header.d=drupal.org header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b="XC0/FzKX"; dkim=fail ("body hash did not verify") header.d=amazonses.com header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=XBaKwROT; spf=pass (lists.piratenpartei.de: domain of security-news-bounces AT drupal.org designates 2605:bc80:3010::133 as permitted sender) smtp.mailfrom=security-news-bounces AT drupal.org; arc=reject ("cv is fail on i=2"); dmarc=pass (policy=none) header.from=drupal.org
  • Feedback-id: ::1.us-west-2.eaokZ1GT8utLqfMHQoyOsEFVrSIzzS6R+14LP6WIIUY=:AmazonSES
  • List-archive: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/>
  • List-id: <security-news.drupal.org>

View online: https://www.drupal.org/sa-contrib-2026-144

Project: SAML SSO - Service Provider [1]
Date: 2026-September-09
Security risk: *Critical* 15 ∕ 25
AC:Complex/A:None/CI:Some/II:Some/E:Theoretical/TD:All [2]
Vulnerability: Weak cryptographic practices

Affected versions: <3.2.0
CVE IDs: CVE-2026-87946
Description: 
This module allows you to configure your Drupal site as a SAML 2.0 Service
Provider so that users can authenticate through an external identity
provider.

The module uses cryptographic constructions that do not align with current
security best practices.

The module performs certain signature comparisons using non constant-time
comparison logic and generates SAML request identifiers using predictable
values derived from non-cryptographic random number generation.

While no practical authentication bypass has been demonstrated as a result of
these weaknesses alone, they may reduce the overall security margin of SAML
authentication workflows.

Solution: 
Install the latest version:

* Upgrade to SAML SSO - Service Provider 3.2.0 [3].

Reported By: 
* Sudhanshu Dhage (sudhanshu0542) [4]

Fixed By: 
* Roushan Kumar Singh (roushan59227) [5]
* Sudhanshu Dhage (sudhanshu0542) [6]

Coordinated By: 
* Bram Driesen (bramdriesen) [7] of the Drupal Security Team
* Greg Knaddison (greggles) [8] of the Drupal Security Team
* Juraj Nemec (poker10) [9] of the Drupal Security Team
* Jess (xjm) [10] of the Drupal Security Team
* Swan Kalata (akalata) [11] of the Drupal Security Team

------------------------------------------------------------------------------
Contribution record [12]

[1] https://www.drupal.org/project/miniorange_saml
[2] https://www.drupal.org/security-team/risk-levels
[3] https://www.drupal.org/project/miniorange_saml/releases/3.2.0
[4] https://www.drupal.org/u/sudhanshu0542
[5] https://www.drupal.org/u/roushan59227
[6] https://www.drupal.org/u/sudhanshu0542
[7] https://www.drupal.org/u/bramdriesen
[8] https://www.drupal.org/u/greggles
[9] https://www.drupal.org/u/poker10
[10] https://www.drupal.org/u/xjm
[11] https://www.drupal.org/u/akalata
[12] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal.org/node/3621839

_______________________________________________
Security-news mailing list -- security-news AT drupal.org
To unsubscribe send an email to security-news-leave AT drupal.org
Unsubscribe at

  • [IT-SecNots] [Security-news] SAML SSO - Service Provider - Critical - Weak cryptographic practices - SA-CONTRIB-2026-144, security-news, 09.09.2026

Archiv bereitgestellt durch MHonArc 2.6.19+.

Seitenanfang