GHSA-g6j2-ch25-5mmv · Severity: high · Ecosystem: nuget — Missing Token Replay Detection in Saml2 Authentication services for ASP.NET
Saml2 Authentication services for ASP.NET (NuGet package Sustainsys.Saml2) greater than 2.0.0, and less than version 2.5.0 has a faulty implementation of Token Replay Detection. Token Replay Detection is an important defence in depth measure for Single Sign On solutions. The 2.5.0 version is patched. Note that version 1.0.1 is not affected. It has a correct Token Replay Implementation and is safe to use. Saml2 Authentication services for ASP.NET (NuGet package Sustainsys.Saml2) greater than 2.0.0, and less than version 2.5.0 have a faulty implementation of Token Replay Detection. Token Replay Detection is an important defense measure for Single Sign On solutions. The 2.5.0 version is patched. Note that version 1.0.1 and prior versions are not affected. These versions have a correct Token Replay Implementation and are safe to use.
Conclusion & alert: CVE-2020-5261 is rated Moderate Risk (56.2/100): CVSS High severity, with medium exploitation likelihood (EPSS 1.20%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.29% | 1.20% | +0.92% |
| 2 | 2025-03-30 | 0.56% | 0.29% | -0.27% |
| 3 | 2025-03-29 | — | 0.56% | — |
Full EPSS history (9 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 8.2 | 3.1 | HIGH |
|
1.8 | 5.8 | [email protected] |
| 6.8 | 3.1 | MEDIUM |
|
1.6 | 5.2 | [email protected] |
| 4.9 | 2.0 | MEDIUM |
|
6.8 | 4.9 | [email protected] |
GHSA-g6j2-ch25-5mmv · Severity: high · Ecosystem: nuget — Missing Token Replay Detection in Saml2 Authentication services for ASP.NET
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| sustainsys | saml2 | >= 2.0.0, < 2.5.0 | cpe:2.3:a:sustainsys:saml2:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://github.com/Sustainsys/Saml2/commit/e58e0a1aff2b1ead6aca080b7cdced55ee6d5241 | Patch Third Party Advisory |
| https://github.com/Sustainsys/Saml2/issues/711 | Issue Tracking Third Party Advisory |
| https://github.com/Sustainsys/Saml2/security/advisories/GHSA-g6j2-ch25-5mmv | Third Party Advisory |