CVE-2024-6800GitHub Enterprise Server SAML XML signature wrapping
What broke
GitHub Enterprise Server accepted a wrapped SAML signature. An attacker with direct network access to the instance could forge a response and provision a privileged user. August 2024. Same family as CVE-2024-4985 and the later CVE-2025-23369 canonicalization bug.
Why it matters
Three GHES SAML IDs in one year is not bad luck. Encrypted assertions plus XML DSig is a surface GitHub kept getting wrong, which is why they later funded the ruby-saml review that found CVE-2024-45409's descendants.
What to do
- Take the August 2024 GHES security update with the May and October SAML fixes.
- Inventory every GHES ACS. DR and lab appliances count.
- If you build a custom SAML SP, do not copy GHES's encrypted-assertion path. Read the SAML 2.0 pitfalls first.
After you patch
A SAML bypass means the service provider accepted an assertion it should have rejected, so anyone who exploited it authenticated as a real user and left a normal-looking log line.
- Revoke every session issued by the affected service provider, then rotate its session signing keys. Patching stops new forgeries and does nothing about sessions already minted.
- Audit administrative accounts and group memberships for changes during the exposure window. Signing in as an administrator is the point of this class, and adding a second account is the standard persistence step.
- Rotate the identity provider signing certificate if the flaw involved signature validation, and confirm the service provider pins the expected certificate rather than trusting anything in the assertion.
- Check your own implementation for the same class: exact-match comparison on verification results, rejection of unexpected signature algorithms, and audience and recency checks on every assertion. See SAML 2.0 and SAML vs OIDC.
Sources
- NVD: CVE-2024-6800
- GitHub GHES security advisories, August 2024
Related identity CVEs
Related on Start with Identity
- CVEGitHub Enterprise Server SAML encrypted-assertion, incomplete fix
The leftover path after CVE-2024-4985. Encrypted SAML assertions on GHES could still be forged. GitHub shipped a second hardening pass. Treat 4985 and 9487 as o
- CVEHaloITSM SAML signature wrapping, log in as any user
HaloITSM accepted a wrapped SAML assertion. An attacker with one valid signature could impersonate any user, including admins. Critical. Another 2024 reminder t
- CVEruby-saml companion signature-wrapping bypass
The pair to CVE-2025-25291. A second signature-wrapping path in ruby-saml lets an attacker forge assertions and impersonate any user. The March 2025 patch was l
- BlogFortinet's January SSO bypass hit boxes already patched for December's SAML bug
CVE-2026-24858 is the follow-on FortiCloud SSO SAML bypass. Devices patched for CVE-2025-59718 and 59719 were still exploitable. Actively exploited. CISA guidan
- GlossaryIdentity Federation
A trust relationship between identity providers and service providers that lets users authenticate once at their home IdP and access applications at the other p
- GlossaryService Provider (SP)
The application that consumes identity assertions from an IdP to grant the user access. In SAML it's the SP; in OIDC the equivalent is the Relying Party. The se
Technique
This CVE is an instance of Federation trust abuse and SAML forgery. A service provider that accepts a SAML assertion it should have rejected treats a forged identity as authenticated, because the failure sits in signature validation code, not in cryptography.