Every CVE whose affected-product data names Timlegge Net::saml2, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (3)
CVE-2026-18108 — CVSS 9.8 (critical): Net::SAML2 versions before 0.86 for Perl allow authentication bypass because _verify_encrypted_assertion accepts an EncryptedAssertion…
CVE-2026-18092 — CVSS 8.1 (high): Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass via XML signature wrapping because new_from_xml reads assertion…
CVE-2026-18089 — CVSS 7.5 (high): Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass by verifying responses against the response-embedded certificate…