[EXTERN] Shibboleth Identity Provider Security Advisory [13 May 2026]

Scott Cantor scott at restingparrotsoftware.com
Fri May 15 13:57:03 UTC 2026



> On May 15, 2026, at 9:49 AM, Martin Hitschel via users <users at shibboleth.net> wrote:
> 
> Hi list,
> FWIW, we've just done a 5.2.2 test upgrade and the DFN-AAI re-published eduGAIN SP metadata feed loads without issues. Apparently the IdP is able to use it, i.e. react upon a persistent NameID declaration in metadata using AACLI. 
> Mayby the issue is OS-dependent? This customer's IdP is on Ubuntu24 with a distribution's tomcat10 and OpenJDK21. We'd even enforced "idp.xml.elementAttributeLimit = 30" but it works still.

The issue people are talking about is what happens if you're not on a supported version and you apply constraints to it.

The 5.2.2 release has separate constraints for metadata parsing because we were warned about this issue, and the property in question does not affect the metadata parsing constraints, that's a separate property. I documented all of that in a new page describing all of the settings we added.

Notably of course, the way people actually blindly consume metadata means that relaxing constraints for metadata isn't exactly safe, but for those following our advice, metadata tends not to be "untrusted XML" in the way messages are.

-- Scott



More information about the users mailing list