AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2020-26290

CRITICAL · CVSS 9.3 EPSS 0.98% Public Exploit

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2020-12-28 · Last synced 2026-08-04

CyberRota Analysis

This is a critical severity vulnerability with a CVSS score of 9.3. Public exploit code or proof-of-concept references have been detected in its references.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2020-26290
Severity
CRITICAL
CVSS
9.3
EPSS
0.98%

Original NVD Description

Dex is a federated OpenID Connect provider written in Go. In Dex before version 2.27.0 there is a critical set of vulnerabilities which impacts users leveraging the SAML connector. The vulnerabilities enables potential signature bypass due to issues with XML encoding in the underlying Go library. The vulnerabilities have been addressed in version 2.27.0 by using the xml-roundtrip-validator from Mattermost (see related references).

Related CVEs

Other vulnerabilities affecting the same vendor(s)