CVE-2024-52596 is an XML External Entity (XXE) vulnerability in SimpleSAMLphp xml-common when it parses untrusted XML, including SAMLResponse messages. The XML parser configuration enabled DTD loading and default-attribute processing, allowing attacker-controlled external entities to be resolved. The issue is fixed in xml-common version 1.19.0.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small, focused exploit PoC consisting of one Python script and a minimal README. The main file, CVE-2024-52806-PoC.py, is a standalone command-line exploit for pre-authentication XXE file read against SimpleSAMLphp, explicitly targeting the SAML ACS endpoint that processes POSTed SAMLResponse data before authentication or signature validation. The script builds a malicious XML payload, base64-encodes it as a SAMLResponse, and POSTs it to the target ACS path. Its core capability is arbitrary file read from the target server using XXE with php://filter wrappers, then exfiltrating the file contents in-band via libxml parse errors rendered in the HTTP response. The default mode is fully self-contained and uses a data: URI to embed the malicious DTD, avoiding any need for outbound connectivity from the target. An optional listener mode starts a local dual-stack HTTP server to host the DTD if inline delivery is impractical. The script also saves the raw response locally and attempts to extract and decode the double-base64 leaked content automatically. Overall, this is a real operational PoC exploit rather than a detector: it performs exploitation, supports configurable target URL/prefix/SP/file path, and returns stolen file contents when successful.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.