Hall of Fame
Back to Hall of Fame Contents Back to WeKan Website

SamlSubjectBleed

CVEIconVulnerability nameDate Responsible Security Disclosure byStarsProcessVulnerabilities
-

SamlSubjectBleed 2026-10-03 alham-rizvi Gold starGold starGold star

Reported by alham-rizvi through coordinated GitHub advisory GHSA-966m-4qgp-j8w4; fixed by xet7.

SAML login matched mutable usernames or email addresses and overwrote the stored NameID. A different IdP subject claiming the same username could take over an existing SAML account. Login now resolves issuer and qualified NameID first, refuses rebinding even when merging is enabled, and stores the binding atomically. Email is no longer marked verified without an explicit assertion attestation. CWE-287; high severity. No CVE assigned. Fix prepared locally for the Upcoming release.

Details

New accounts bind issuer, NameID, NameID format and both qualifiers. Returning subjects can change profile attributes without changing account identity. Transient or malformed subjects are rejected. Opt-in linking requires explicit verified matching email on both sides, and a conditional database update prevents concurrent links from replacing each other.

Upgrade: legacy bindings without issuer require independent identity verification and server-side repair by an administrator. The next assertion is never trusted to fill missing scope. See the SAML upgrade instructions.

Detection

Conflicting subjects are summarized as SamlSubjectBleed in Admin Panel / Problems. Logging failure never permits login. Missing legacy scope is refused without an attack record, because an ordinary login after upgrade reaches that path.

Verification

Behavioral tests execute the login handler, including real signed assertions with the same email and different NameIDs. Negative coverage checks the tracked source for duplicate binding writers. Tests also cover repeated login, attribute changes, qualifiers, legacy accounts, verification claims and concurrent writes.

Source fix and regression coverage

Browser verification, 2026-10-03

Using build.sh source-mode startup and isolated local MongoDB, Chromium, Firefox and WebKit each passed all three focused scenarios: SAML error display, a real signed login followed by a different-subject takeover refusal, and native ZIP decompression-limit refusal followed by a valid import. The macOS Firefox launch initially failed on protected shared app data; isolating both Gecko app-data roots resolved it, with probes enabled and all browser sandboxes retained. Production identity providers were not tested.