Skip to finding
important · Edge — SAML

A self-signed SAML response can impersonate any identity accepted by MojoX::Authentication.

Affects

MojoX::Authentication, a Perl authentication library used by Mojolicious applications for local and SAML2 login.

The parser lacked a configured trust anchor, so an attacker could sign an assertion naming the target account and have it checked against the certificate embedded in that response.

Detail and 2 sources
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Monday, September 7, 2026