CVE-2021-21239
Python vulnerability analysis and mitigation

Overview

PySAML2 versions before 6.5.0 contained a cryptographic signature verification vulnerability (CVE-2021-21239) discovered in January 2021. The vulnerability affected the default CryptoBackendXmlSec1 backend, which is used to verify signatures of SAML documents (GitHub Advisory, NVD).

Technical details

The vulnerability stems from the default CryptoBackendXmlSec1 backend using the xmlsec1 binary to verify signatures without properly restricting the key types. By default, xmlsec1 accepts any type of key found within the given document, instead of being explicitly configured to only use x509 certificates for SAML document signature verification (GitHub Advisory, Debian LTS).

Impact

The vulnerability allows attackers to potentially alter SAML documents by exploiting the improper signature verification. All users of pysaml2 that use the default CryptoBackendXmlSec1 backend and need to verify signed SAML documents are impacted (GitHub Advisory, Ubuntu Notice).

Exploitability

The vulnerability could be exploited by an attacker to manipulate SAML documents due to the improper validation of cryptographic signatures. The issue was rated as Critical severity, indicating a significant security risk (GitHub Advisory).

Mitigation and workarounds

The vulnerability was patched in PySAML2 version 6.5.0, released on January 20, 2021. Users should upgrade to this version or later to address the security issue. The fix involves explicitly configuring xmlsec1 to only use x509 certificates for the verification process of SAML document signatures (GitHub Release, GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-63003MEDIUM6.5
  • Python logoPython
  • django-cms
NoYesAug 20, 2026
CVE-2026-54624MEDIUM6.5
  • Python logoPython
  • django-cms
NoYesAug 20, 2026
CVE-2026-54622MEDIUM6.5
  • Python logoPython
  • django-cms
NoYesAug 20, 2026
CVE-2026-75526MEDIUM4.4
  • Python logoPython
  • django-cms
NoYesAug 20, 2026
CVE-2026-61663MEDIUM4.3
  • Python logoPython
  • django-cms
NoYesAug 20, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management