How to use this reference
Editorial reasoning: signatures protect the generated representation, not the authority of each input used to construct it. Keep profile text separate from authorization-claim structure, use context-correct serialization before signing, and review which upstream actors may supply claims consumed as roles. A signature check alone cannot repair a compromised issuance boundary.
Before reading
- SAML issuer/relying-party roles, XML contexts and claim-based authorization
Context and limits
- The advisory identifies master/v2.10.2 as affected and 2.13.0 as patched; it does not establish a complete affected-version interval. Exposure requires user-controlled values reaching assertion generation and a relying party trusting the resulting attributes.
- The published example supports added attributes being parsed; downstream privileged application actions are conditional consequences, not evidence of a breached deployment.
- tngan published the advisory; RootUp is credited as reporter in both advisory and release notes. The 2.13.0 release explicitly references this advisory. Its displayed May 14 timestamp omits the year in retrieved text, so no full patch date is asserted. Resource edition remains null.
Sources and provenance
- SAML attribute-generation integrity advisory samlify · reviewed 2026-10-03
- Release v2.13.0 samlify · reviewed 2026-10-03
Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.