GitHub Enterprise Server contains an improper verification of cryptographic signature vulnerability in its SAML single sign-on authentication handling. According to the provided content, the flaw allowed signature spoofing for unauthorized internal users, enabling a malicious existing user to present a forged or ambiguously processed SAML assertion that was accepted as valid. The issue is associated in the supplied context with libxml2/XML processing quirks affecting signature verification behavior. Only deployments using SAML SSO were impacted; instances not using SAML single sign-on, or scenarios where the attacker was not already an existing user, were not affected. The vulnerability affected all GitHub Enterprise Server versions prior to 3.12.14, 3.13.10, 3.14.7, 3.15.2, and 3.16.0.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a Python proof-of-concept exploit targeting SAML-based authentication systems. The main file, 'main.py', takes a base64-encoded SAML response and a target NameID as input. It decodes and parses the SAML XML, manipulates the XML structure to remove and re-insert signatures, alters assertion IDs, injects XML entities, and sets the NameID to an attacker-supplied value. The script then re-encodes the mutated SAML response, which can be used to attempt to bypass signature validation and impersonate arbitrary users in vulnerable SAML implementations. The exploit demonstrates a SAML signature bypass technique and is intended for testing or research purposes. The repository is minimal, containing only the exploit script and a placeholder README.
This repository contains a proof-of-concept exploit for CVE-2025-23369, targeting SAML service providers that use libxml2 for XML parsing. The exploit is implemented as a Ruby script (exploit.rb) that takes a Base64-encoded SAML response file and a target NameID as input. It decodes and parses the SAML response, manipulates the XML structure and signature elements, and injects XML entities to exploit quirks in libxml2's handling of XML signatures. The script then outputs a mutated, Base64-encoded SAML response that can be used to impersonate an arbitrary user if submitted to a vulnerable SAML service provider. The repository also includes a brief README with a link to a detailed write-up. No network endpoints or remote services are directly targeted by the script; it operates on local files and is intended to be used in scenarios where the attacker can submit the crafted SAML response to a vulnerable service.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
High-severity improper cryptographic signature verification vulnerability in GitHub Enterprise Server affecting SAML SSO, enabling signature spoofing and privilege escalation for existing users under certain conditions.
A SAML authentication bypass affecting GitHub Enterprise, leveraging libxml2 XML parsing quirks (notably internal caching behavior) to produce unexpected processing results that can be abused to bypass signature/validation expectations.
A SAML-related vulnerability referenced as part of a wave of newly disclosed SAML bugs; no further technical detail is provided in the content.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.