Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2020-26290 Details

Description

Dex is a federated OpenID Connect provider written in Go. In Dex before version 2.27.0 there is a critical set of vulnerabilities which impacts users leveraging the SAML connector. The vulnerabilities enables potential signature bypass due to issues with XML encoding in the underlying Go library. The vulnerabilities have been addressed in version 2.27.0 by using the xml-roundtrip-validator from Mattermost (see related references).

Metrics

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

URLSource(s)Tag(s)
https://github.com/dexidp/dex/commit/324b1c886b407594196113a3dbddebe38eecd4e8 CVEPatchThird Party Advisory
https://github.com/dexidp/dex/releases/tag/v2.27.0 CVEThird Party Advisory
https://github.com/dexidp/dex/security/advisories/GHSA-m9hp-7r99-94h5 CVEThird Party Advisory
https://github.com/mattermost/xml-roundtrip-validator/blob/master/advisories/unstable-attributes.md CVENot ApplicableThird Party Advisory
https://github.com/mattermost/xml-roundtrip-validator/blob/master/advisories/unstable-directives.md CVENot ApplicableThird Party Advisory

see all 16 references

Weakness Enumeration

CWE-IDCWE NameSource
CWE-347Improper Verification of Cryptographic Signature[email protected]

Affected Products

ProductVersions
linuxfoundation dex
< 2.27.0

CPE

  • cpe:2.3:a:linuxfoundation:dex:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

4 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2020-26290
NVD Published Date:
Dec 28, 2020
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2020-26290 Details - Not Deferred