← Back to browse · API

CVE-2025-25291

Severity
CRITICAL
CVSS
9.3
EPSS
0.2026
Risk score
44.29
CISA KEV
No
PoC
No
Published
2025-03-12
Modified
2025-11-03
First seen
2026-08-07
Aliases
EUVD-2025-6415, GHSA-4VC4-M8QH-G8JM
Products
SAML-Toolkits:Ruby-SAML 1.13.0, < 1.18.0, SAML-Toolkits:Ruby-SAML < 1.12.4
Sources
euvd EUVD-2025-6415

Description

ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. An authentication bypass vulnerability was found in ruby-saml prior to versions 1.12.4 and 1.18.0 due to a parser differential. ReXML and Nokogiri parse XML differently; the parsers can generate entirely different document structures from the same XML input. That allows an attacker to be able to execute a Signature Wrapping attack. This issue may lead to authentication bypass. Versions 1.12.4 and 1.18.0 fix the issue.

References