Microsoft.IdentityModel.Tokens.Saml is vulnerable to Denial of Service (DoS)
75
High Risk
The Microsoft.IdentityModel.Tokens.Saml component reads SAML security tokens and assertions from request input. A crafted SAML token drives a loop whose exit condition is never reached while deserializing untrusted data, so processing never completes. Before the fix an unauthenticated caller can send such a token over the network to exhaust CPU and memory and stop the service from answering legitimate requests. The fix corrects the loop so parsing terminates and the malformed token is rejected instead of looping indefinitely.
You are affected if you are using a version that falls within the vulnerable range and your application processes SAML tokens or assertions with the affected component.
Microsoft.IdentityModel.Tokens.Saml is vulnerable to Denial of Service (DoS) in versions 0.0.1 - 5.7.0, 6.5.0 - 7.7.2 and 8.0.0 - 8.19.1.
Upgrade the Microsoft.IdentityModel.Tokens.Saml library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant