SAML SSO - Service Provider
11 security fixes in one update. SAML SSO - Service Provider fixed 11 separate security bugs this week: 2 cross site scripting, 1 weak cryptographic practices, 1 open redirect, 1 improper certificate validation, 1 improper access control, 1 server side request forgery, 1 insufficient replay protection, 1 information disclosure, 1 embedded credentials, 1 authentication bypass. One update covers all of them. The most serious, SA-CONTRIB-2026-144, is explained here and the full list is at the end of the card.
The module uses outdated methods for generating random numbers and checking digital signatures. Anyone visiting the site could potentially exploit these weaknesses to weaken the overall security of the login process to read private information and change some data.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youAny site using this module.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this critical. Cyber Essentials expects a fix within 14 days. Do it this week.
Tell your developerUpdate SAML SSO - Service Provider to 3.2.0.
For developers: what the fix changed
It is unclear where the predictable random number generation is fixed as the diff is truncated, but the signature comparison logic is updated in the verify function of src/Utilities.php to use strict type checking. The update also introduces unmentioned security improvements including XML external entity and server side request forgery protections.
The fix is not clearly separable from the other changes in this release, so treat the summary above as a pointer rather than a finding.
Also in this release The release removes unused configuration and routes, adds local relay state validation, and implements replay attack protection for SAML assertions.
config/install/miniorange_saml.settings.yml+0 −1config/schema/miniorange_saml.schema.yml+19 −10miniorange_saml.install+8 −0miniorange_saml.routing.yml+1 −9src/Api/MoAuthApi.php+0 −46src/Controller/MiniorangeSamlController.php+5 −44src/Form/MiniorangeSpInfo.php+97 −6src/Form/MiniorangeTrial.php+0 −51src/MiniOrangeSamlAcs.php+175 −46src/MiniorangeSamlConstant.php+0 −3src/MiniorangeSamlSpRegistration.php+0 −414src/MiniorangeSamlSupport.php+1 −1
- Critical · Weak cryptographic practices · SA-CONTRIB-2026-144
- Critical · Open redirect · SA-CONTRIB-2026-143
- Critical · Improper certificate validation · SA-CONTRIB-2026-142
- Critical · Improper access control · SA-CONTRIB-2026-141
- Moderately critical · Server Side Request Forgery · SA-CONTRIB-2026-151
- Moderately critical · Insufficient replay protection · SA-CONTRIB-2026-150
- Moderately critical · Information disclosure · SA-CONTRIB-2026-149
- Moderately critical · Embedded credentials · SA-CONTRIB-2026-148
- Moderately critical · Cross site scripting · SA-CONTRIB-2026-147
- Moderately critical · Cross site scripting · SA-CONTRIB-2026-146
- Moderately critical · Authentication bypass · SA-CONTRIB-2026-145