HOL LogoHOL

Product

  • Guard overview
  • Features
  • Product preview
  • Comparison
  • Pricing
  • Enterprise
  • Open App
  • Install Guard

AI tools

  • All AI tools
  • Codex
  • Claude Code
  • Cursor
  • Gemini CLI
  • OpenCode
  • Hermes
  • OpenClaw
  • GitHub Copilot CLI
  • Antigravity
  • Kimi
  • Grok
  • Pi / Oh My Pi
  • Zcode

Extensions

  • All extensions
  • Command coverage
  • MCP server coverage
  • Core safety
  • Data and resilience
  • Cloud and infrastructure

Resources

  • AI security hub
  • AI tool security
  • Safe labs
  • Redacted warnings
  • Advisories
  • Active CVEs
  • Security guides
  • Docs
  • Research
  • Affiliates

AI Agents

  • Home
  • Browse Agents
  • Registry Dashboard
  • Register Agent
  • Docs

Plugins

  • Browse Plugins
  • Plugin Launches
  • Submit Plugin

Extensions

  • All extensions
  • Command coverage
  • MCP server coverage
  • Core safety
  • Data and resilience
  • Cloud and infrastructure

Best Plugins

  • Best Claude Plugins
  • Best Codex Plugins
  • Best Grok Plugins
  • Best Kimi Plugins
  • Best DeepSeek Plugins
  • Best Antigravity Plugins
  • Best MCP Plugins
  • Best Cursor Plugins
  • Best OpenCode Plugins

Security

  • HOL Guard
  • CIGAR

Open Source

  • Open Source Impact

Points

  • HOL Points
  • Leaderboard
  • Analytics

Events

  • Patchwork (Ended)
  • OpenConvAI Hackathon (Ended)
  • Hedera x AI Demo Day (Ended)
  • Hackathons (Ended)

Standards

  • Overview
  • Standards Library
  • Universal Identity
  • Auditable Points
  • Agent Adapter Registry
  • Files & Hashinals
  • Data Registries
  • Identity Metadata
  • Agent Communication
  • AppNet Accounts

Tools

  • Hashnet MCP Server
  • Standards SDK
  • Conversational Agent

Library Docs

  • Guard Docs
  • Registry Broker Docs
  • Go SDK
  • Python SDK

Resources

  • Tutorials
  • Overview
  • Careers
  • Members
  • Blog
  1. Home
  2. Blog
  3. Sso

Sso

1 post tagged with “Sso”

CVE-2026-18108: Net::SAML2 Authentication Bypass via Unsigned Encrypted Assertions (CVSS 9.8)
cvesecurityvulnerability

CVE-2026-18108: Net::SAML2 Authentication Bypass via Unsigned Encrypted Assertions (CVSS 9.8)

Net::SAML2 before 0.86 accepts decrypted SAML assertions that carry no XML signature. Any party can encrypt an unsigned assertion to an SP's published certificate and authenticate as an arbitrary user. Affects Azure AD, Okta, Google, ADFS, and all other IdPs.

Aug 4, 2026
Read
Docs
  • Documentation Index
  • Developer Hub
  • API Reference
  • Root OpenAPI
  • Registry OpenAPI
  • Run in Postman
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Plugins
  • Browse Plugins
  • Plugin Launches
  • Best Claude Plugins
  • Best Codex Plugins
  • Best Grok Plugins
  • Best Kimi Plugins
  • Best DeepSeek Plugins
  • Best Antigravity Plugins
  • Best MCP Plugins
  • Best Cursor Plugins
  • Best OpenCode Plugins
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • About HOL
  • Contact
  • Blog
  • GitHub
  • Privacy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.