← Back to feed
AwarenessEmerging1 sourceDec 10, 2025 · 12:32via PortSwigger Research

The Fragile Lock: Novel Bypasses For SAML Authentication

Brief

TLDR This post shows how to achieve a full authentication bypass in the Ruby and PHP SAML ecosystem by exploiting several parser-level inconsistencies: including attribute pollution, namespace confusi

Read more on PortSwigger Research