/
DirectorySecurity Advisories
Sign In
Security Advisories

CVE-2020-26290

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2020-26290

CGA ID

CGA-w29q-h459-6537

Severity

9.6

Critical

CVSS V3

Description

Dex is a federated OpenID Connect provider written in Go. In Dex before version 2.27.0 there is a critical set of vulnerabilities which impacts users leveraging the SAML connector. The vulnerabilities enables potential signature bypass due to issues with XML encoding in the underlying Go library. The vulnerabilities have been addressed in version 2.27.0 by using the xml-roundtrip-validator from Mattermost (see related references).

References

Affected packages


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Products

Chainguard ContainersChainguard LibrariesChainguard VMs