{"api_version":"v1","generated_at":"2026-10-07T15:05:00+00:00","product":{"cve_count":4,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-simplesamlphp-saml2-1b74e87b4210","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/saml2","name":"saml2","next_cursor":null,"observations":[{"affected":"saml2: >= 4.19.2, < 4.19.3, >= 4.20.2, < 4.20.3","affected_versions_present":true,"cve_id":"CVE-2026-49289","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-49289","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-19T18:04:15.406Z","patch_url":"","primary_source":"","published":"2026-08-19T14:48:52.694Z"},{"affected":"saml2: < 4.19.3, >= 4.20.0, < 4.20.2, >= 5.0.0, < 5.0.6, >= 6.0.0, < 6.2.1","affected_versions_present":true,"cve_id":"CVE-2026-49283","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-49283","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-19T18:19:10.978Z","patch_url":"","primary_source":"","published":"2026-08-19T14:47:05.519Z"},{"affected":"< 4.17.0; >= 5.0.0-alpha.1, < 5.0.0-alpha.20","affected_versions_present":true,"cve_id":"CVE-2025-27773","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-27773","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-05-09T20:03:38.107Z","patch_url":"","primary_source":"","published":"2025-03-11T19:04:52.135Z"},{"affected":"< 4.6.14; >= 5.0.0-alpha.1, < 5.0.0-alpha.18","affected_versions_present":true,"cve_id":"CVE-2024-52806","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-52806","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-12-02T19:12:33.197Z","patch_url":"","primary_source":"","published":"2024-12-02T16:18:43.485Z"}],"source_generated_at":"2026-10-07T06:21:30.017Z","vendor":"simplesamlphp"}}
