@bergie @markstos @ploer Just wanted to make sure this was on your radar. It looks like passport-saml does its own XML parsing, but is it safe from these new vulnerabilities?
https://developer.okta.com/blog/2018/02/27/a-breakdown-of-the-new-saml-authentication-bypass-vulnerability