Report: Ultimate Guide: CVE-2025-65954 - SimpleSAMLphp-casserver has an Open Redirect vulnerability via logout

Report: Ultimate Guide: CVE-2025-65954 - SimpleSAMLphp-casserver has an Open Redirect vulnerability via logout

CVE ID :CVE-2025-65954 Published : May 18, 2026, 8:16 p.m. | 1 hour, 17 minutes ago Description :SimpleSAMLphp-casserver is a CAS 1.0 and 2.0 compliant CAS server in the form of a SimpleSAMLphp module. In versions below 6.3.1 and 7.0.0, the logout endpoint accepts a url query parameter to redirect to. casserver treats that url as trusted, and either (depending on configuration) redirects the browser there, or shows a

CVE Details

Published
May 18, 2026