It was found that python-pysaml2 is vulnerable to an XML external entity attack. python-pysaml2 does not sanitize SAML XML requests or responses.
References:
http://seclists.org/oss-sec/2017/q1/50 https://bugs.debian.org/850716
Upstream bug:
https://github.com/rohe/pysaml2/issues/366
Proposed patch (! actually fixes Bug 1415710):
https://github.com/rohe/pysaml2/pull/379
Last updated 25 August 2025