GHSA-jrrg-99xh-5j2q
HIGHCVE-2026-46491simplesamlphp-module-casserver builds file paths for the file-based CAS ticket store by directly concatenating the configured ticket directory with an attacker-controlled ticket identifier. Public CAS validation/proxy endpoints pass attacker-controlled ticket / pgt query parameters into this store.
- Affected
- <= 7.0.2
- Fixed in
- 7.0.3
- Weakness
- CWE-22
- Published
- 2026-05-15
- Source
- github