Ruby-Saml
SAML-Toolkits · 7 CVEs
CVE-2025-66568
CRITICAL
ruby-saml Libxml2 Canonicalization errors can bypass Digest/Signature validation
Dec 9, 2025
CVE-2025-66567
CRITICAL
ruby-saml has a SAML authentication bypass due to namespace handling (parser differential)
Dec 9, 2025
CVE-2025-54572
MEDIUM
Ruby SAML DOS vulnerability with large SAML response
Jul 30, 2025
CVE-2025-25292
CRITICAL
Ruby SAML vulnerable to SAML authentication bypass due to namespace handling (parser differential)
Mar 12, 2025
CVE-2025-25291
CRITICAL
ruby-saml vulnerable to SAML authentication bypass due to DOCTYPE handling (parser differential)
Mar 12, 2025
CVE-2025-25293
HIGH
ruby-saml vulnerable to Remote Denial of Service (DoS) with compressed SAML responses
Mar 12, 2025
CVE-2024-45409
CRITICAL
The Ruby SAML library vulnerable to a SAML authentication bypass via Incorrect XPath selector
Sep 10, 2024
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2025-66568 | ruby-saml Libxml2 Canonicalization errors can bypass Digest/Signature validation | CRITICAL | 0.23% | Dec 9, 2025 |
| CVE-2025-66567 | ruby-saml has a SAML authentication bypass due to namespace handling (parser differential) | CRITICAL | 0.39% | Dec 9, 2025 |
| CVE-2025-54572 | Ruby SAML DOS vulnerability with large SAML response | MEDIUM | 0.40% | Jul 30, 2025 |
| CVE-2025-25292 | Ruby SAML vulnerable to SAML authentication bypass due to namespace handling (parser differential) | CRITICAL | 65.09% | Mar 12, 2025 |
| CVE-2025-25291 | ruby-saml vulnerable to SAML authentication bypass due to DOCTYPE handling (parser differential) | CRITICAL | 20.96% | Mar 12, 2025 |
| CVE-2025-25293 | ruby-saml vulnerable to Remote Denial of Service (DoS) with compressed SAML responses | HIGH | 1.53% | Mar 12, 2025 |
| CVE-2024-45409 | The Ruby SAML library vulnerable to a SAML authentication bypass via Incorrect XPath selector | CRITICAL | 10.68% | Sep 10, 2024 |
Showing 1 to 7 of 7 CVEs