One advantage of SAML over OIDC - they standardized IDP initiated login, so you can skip the "login using..." button when sending an already logged in user to a third party system.
But the various XML canonicalization specs, XML transforms, embedding X509 certificates, all the mess they created to be able to embed signatures inside XML messages instead of just sending them separate from the assertions, is horrible to get right and will be a source of more security bugs for many, many years to come. https://www.google.com/search?q=canonicalization+CVE+SAML