CVE-2026-49454 - Relyra SAML SignatureValue not cryptographically verified -> authentication bypass
CVE ID :CVE-2026-49454 Published : June 18, 2026, 8:52 p.m. | 4 hours, 17 minutes ago Description :Relyra is a strict-by-default SAML 2.0 Service Provider library for Elixir and Phoenix. Versions 1.0.0 and 1.1.0 accept forged SAML signatures because SignatureValue was not cryptographically...