NPM · AUGUST 2026 · EARLY WARNING

Picketlink Federation SAML Vulnerability: Early Warning Issued

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
Severity
CRITICAL
CVSS
9.8
Affected component
picketlink federation saml (npm)
Patched version
Not yet available
CVE-2026-10579

An early warning has been issued for a critical flaw in the Picketlink Federation SAML package that reportedly allows unauthenticated attackers to forge assertions and gain unauthorized access.

What happened

A critical flaw has been identified in the Picketlink Federation SAML package, tracked as CVE-2026-10579. The vulnerability lies in the unsolicited response handler, which appears to accept forged assertions without proper verification or validation. This could permit an unauthenticated attacker to authenticate as any principal in any role, potentially leading to information disclosure, access to restricted operations, or other security flaws. The flaw was first flagged on 2026-08-11T09:17:12.260000+00:00.

Professional software engineers using the Picketlink Federation SAML package should assess their exposure by reviewing their current implementations and dependencies. Although no authoritative version range has been published yet, it is advisable to consider this vulnerability as potentially affecting all versions until further notice.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If picketlink federation saml is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

If your project depends on the Picketlink Federation SAML package, you may be affected. Review your dependencies and consider this vulnerability as potentially impacting all versions until further notice.

What should I do right now?

Monitor for updates on the affected package and consider alternative solutions until a patch is available. Review your authentication and authorization mechanisms for potential exposure.

Is there a patch available?

No official fix has been published yet. Continue to monitor the sources for updates.

How severe is this vulnerability?

The vulnerability is classified as CRITICAL with a CVSS score of 9.8.

Sources

Join the 0Day waitlist →

← Back to all threats