Drupal security updates, in plain English · Module

SAML SSO - Service Provider

2,587 sites report using it · on drupal.org · 3 security updates explained here

This module lets users log into the website using an external identity provider like Google or Microsoft.

Below is every security update for SAML SSO - Service Provider that this site has covered, newest first. Each one says who could exploit it, whether it applies to your site, how urgent it is, and what to tell your developer. If your site uses this module and you are not sure which version, that is the first question to ask whoever looks after it.

SAML SSO - Service Provider

Critical · 2,587 sites report using it · 11 security fixes · Week of 9 September 2026

11 security fixes in one update. SAML SSO - Service Provider fixed 11 separate security bugs this week: 2 cross site scripting, 1 weak cryptographic practices, 1 open redirect, 1 improper certificate validation, 1 improper access control, 1 server side request forgery, 1 insufficient replay protection, 1 information disclosure, 1 embedded credentials, 1 authentication bypass. One update covers all of them. The most serious, SA-CONTRIB-2026-144, is explained here and the full list is at the end of the card.

The module uses outdated methods for generating random numbers and checking digital signatures. Anyone visiting the site could potentially exploit these weaknesses to weaken the overall security of the login process to read private information and change some data.

  • Who could do thisAnyone visiting the site. No login needed.
  • Does it apply to youAny site using this module.
  • Has it been used in attacksNo sign of it.
  • How urgentDrupal rates this critical. Cyber Essentials expects a fix within 14 days. Do it this week.

Tell your developerUpdate SAML SSO - Service Provider to 3.2.0.

For developers: what the fix changed

This release carries 11 security fixes. The summary below is for SA-CONTRIB-2026-144, the most serious of them.

It is unclear where the predictable random number generation is fixed as the diff is truncated, but the signature comparison logic is updated in the verify function of src/Utilities.php to use strict type checking. The update also introduces unmentioned security improvements including XML external entity and server side request forgery protections.

The fix is not clearly separable from the other changes in this release, so treat the summary above as a pointer rather than a finding.

Also in this release The release removes unused configuration and routes, adds local relay state validation, and implements replay attack protection for SAML assertions.

3.1.4 to 3.2.0 1 commit, 16 files.

  • config/install/miniorange_saml.settings.yml +0 −1
  • config/schema/miniorange_saml.schema.yml +19 −10
  • miniorange_saml.install +8 −0
  • miniorange_saml.routing.yml +1 −9
  • src/Api/MoAuthApi.php +0 −46
  • src/Controller/MiniorangeSamlController.php +5 −44
  • src/Form/MiniorangeSpInfo.php +97 −6
  • src/Form/MiniorangeTrial.php +0 −51
  • src/MiniOrangeSamlAcs.php +175 −46
  • src/MiniorangeSamlConstant.php +0 −3
  • src/MiniorangeSamlSpRegistration.php +0 −414
  • src/MiniorangeSamlSupport.php +1 −1

Full diff, 3.1.4 to 3.2.0

The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.

All 11 security bugs this update fixes, worst first. Each link is the drupal.org notice for that one.

SAML SSO - Service Provider

Critical · 2,587 sites report using it · SA-CONTRIB-2026-031 · on drupal.org · Week of 1 April 2026

The module fails to block access properly. A person without an account could skip the login process to enter the site. Once inside they could read any private information and change any data or website code.

  • Who could do thisAnyone visiting the site. No login needed.
  • Does it apply to youAny site using this module.
  • Has it been used in attacksNo sign of it.
  • How urgentDrupal rates this critical. Cyber Essentials expects a fix within 14 days. Do it this week.

Tell your developerUpdate SAML SSO - Service Provider to 3.1.4.

For developers: what the fix changed

The fix uncomments `exit();` statements in `src/Utilities.php` to properly halt execution when SAML signature validation fails, preventing the authentication bypass.

Also in this release Added XSS filtering to test results and audience validation, and disabled network access in XML loading to prevent XXE.

3.1.3 to 3.1.4 1 commit, 2 files.

  • src/MiniOrangeSamlAcs.php +7 −6
  • src/Utilities.php +8 −8 fix

Full diff, 3.1.3 to 3.1.4

The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.

SAML SSO - Service Provider

Critical · 2,587 sites report using it · SA-CONTRIB-2026-018 · on drupal.org · Week of 25 February 2026

The module does not properly clean user input. Someone could use this to uncover private details or alter existing information.

  • Who could do thisAnyone visiting the site. No login needed.
  • Does it apply to youAny site using this module.
  • Has it been used in attacksNo sign of it.
  • How urgentDrupal rates this critical. Cyber Essentials expects a fix within 14 days. Do it this week.

Tell your developerUpdate SAML SSO - Service Provider to 3.1.3.

For developers: what the fix changed

The fix sanitises the status code parameter using Xss::filter in the showErrorMessage method of src/MiniOrangeSamlAcs.php.

3.1.2 to 3.1.3 1 commit, 1 file.

  • src/MiniOrangeSamlAcs.php +5 −3 fix

Full diff, 3.1.2 to 3.1.3

The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.

Not sure what your site is running?

Send me your Drupal site's address.

I'll tell you what I can see from outside, what the Drupal 10 end of life on 9 December means for it, and what it would cost to have me keep it patched. There's no charge for that and no obligation. peter@peterbrady.co.uk


Get in touch

Tell me who you are, what your organisation does, and what you need. That might be a Drupal site that needs looking after, an upgrade to get done before December, or an agency that needs Drupal cover.

If I can help, I'll say so and suggest a call. If I can't, I'll tell you straight away rather than waste your time.

peter@peterbrady.co.uk

For context: I work mainly with UK charities, membership bodies and research organisations, and with the agencies that look after their websites. Not recruiters.

Or start smaller and connect with me on LinkedIn. That's where I post what I find digging around in charity and grants data, and where the free tools turn up first.