← Back to browse · API

CVE-2025-25292

Severity
CRITICAL
CVSS
9.3
EPSS
0.64822
Risk score
59.89
CISA KEV
No
PoC
No
Published
2025-03-12
Modified
2025-11-03
First seen
2026-08-07
Aliases
EUVD-2025-6414, GHSA-754F-8GM6-C4R2
Products
SAML-Toolkits:Ruby-SAML 1.13.0, < 1.18.0, SAML-Toolkits:Ruby-SAML < 1.12.4
Sources
euvd EUVD-2025-6414

Description

ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. An authentication bypass vulnerability was found in ruby-saml prior to versions 1.12.4 and 1.18.0 due to a parser differential. ReXML and Nokogiri parse XML differently, the parsers can generate entirely different document structures from the same XML input. That allows an attacker to be able to execute a Signature Wrapping attack. This issue may lead to authentication bypass. Versions 1.12.4 and 1.18.0 contain a patch for the issue.

References