cve/2021/CVE-2021-27736.md
2025-09-29 21:09:30 +02:00

701 B

CVE-2021-27736

Description

FusionAuth fusionauth-samlv2 before 0.5.4 allows XXE attacks via a forged AuthnRequest or LogoutRequest because parseFromBytes uses javax.xml.parsers.DocumentBuilderFactory unsafely.

POC

Reference

No PoCs from references.

Github