Onelogin / Ruby-Saml
9 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-66568 | ruby-saml Libxml2 Canonicalization errors can bypass Digest/Signature validation | CRITICAL | 9.3 | Dec 9, 2025 |
| CVE-2025-66567 | ruby-saml has a SAML authentication bypass due to namespace handling (parser differential) | CRITICAL | 9.3 | Dec 9, 2025 |
| CVE-2025-25292 | Ruby SAML vulnerable to SAML authentication bypass due to namespace handling (parser differential) | CRITICAL | 9.3 | Mar 12, 2025 |
| CVE-2025-25291 | ruby-saml vulnerable to SAML authentication bypass due to DOCTYPE handling (parser differential) | CRITICAL | 9.3 | Mar 12, 2025 |
| CVE-2025-25293 | ruby-saml vulnerable to Remote Denial of Service (DoS) with compressed SAML responses | HIGH | 7.7 | Mar 12, 2025 |
| CVE-2024-45409 | The Ruby SAML library vulnerable to a SAML authentication bypass via Incorrect XPath selector | CRITICAL | 9.9 | Sep 10, 2024 |
| CVE-2015-20108 | xml_security.rb in the ruby-saml gem before 1.0.0 for Ruby allows XPath injection and code execution because prepared statements are not used. | CRITICAL | 9.8 | May 27, 2023 |
| CVE-2017-11428 | Multiple SAML libraries may allow authentication bypass via incorrect XML canonicalization and DOM traversal | CRITICAL | 9.8 | Apr 17, 2019 |
| CVE-2016-5697 | Ruby-saml before 1.3.0 allows attackers to perform XML signature wrapping attacks via unspecified vectors. | HIGH | 7.5 | Jan 23, 2017 |
Showing 1 to 9 of 9 CVEs