📦 Ruby Saml

by Onelogin

🔍 What is Ruby Saml?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-66567

CRITICAL CVSS 9.1 Dec 9, 2025

The ruby-saml library contains an authentication bypass vulnerability due to XML parsing differences between ReXML and Nokogiri, allowing attackers to execute Signature Wrapping attacks. This affects ...

CVE-2025-66568

CRITICAL CVSS 9.1 Dec 9, 2025

The ruby-saml library versions up to 1.12.4 are vulnerable to authentication bypass via Signature Wrapping attacks. Attackers can exploit libxml2's canonicalization behavior on invalid XML to bypass S...

CVE-2025-25291

CRITICAL CVSS 9.8 Mar 12, 2025

CVE-2025-25291 is an authentication bypass vulnerability in ruby-saml that allows attackers to bypass SAML single sign-on authentication via signature wrapping attacks. The vulnerability stems from pa...

CVE-2024-45409

CRITICAL CVSS 10.0 Sep 10, 2024

CVE-2024-45409 is a critical authentication bypass vulnerability in the Ruby SAML library where SAML response signatures are not properly verified. This allows unauthenticated attackers with access to...

CVE-2015-20108

CRITICAL CVSS 9.8 May 27, 2023

This vulnerability in the ruby-saml gem allows XPath injection leading to remote code execution. Attackers can execute arbitrary code on systems using vulnerable versions of the gem. Any Ruby applicat...

CVE-2025-25293

HIGH CVSS 7.5 Mar 12, 2025

This vulnerability in ruby-saml allows remote attackers to cause Denial of Service (DoS) by sending specially crafted compressed SAML responses. The library checks message size before decompression, e...