- Description
- The ruby-saml library implements the client side of an SAML authorization. Versions up to and including 1.12.4, are vulnerable to authentication bypass through the libxml2 canonicalization process used by Nokogiri for document transformation, which allows an attacker to execute a Signature Wrapping attack. When libxml2’s canonicalization is invoked on an invalid XML input, it may return an empty string rather than a canonicalized node. ruby-saml then proceeds to compute the DigestValue over this empty string, treating it as if canonicalization succeeded. This issue is fixed in version 1.18.0.
- Source
- security-advisories@github.com
- NVD status
- Analyzed
- Products
- ruby-saml
CVSS 4.0
- Type
- Secondary
- Base score
- 9.3
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- CRITICAL
CVSS 3.1
- Type
- Primary
- Base score
- 9.1
- Impact score
- 5.2
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- Severity
- CRITICAL
- security-advisories@github.com
- CWE-347
- Hype score
- Not currently trending
#VulnerabilityReport #AuthenticationBypass Critical Authentication Bypass Flaws Discovered in Ruby SAML Library (CVE-2025-66567 & CVE-2025-66568) https://t.co/K9r7F9lQs6
@Komodosec
15 Jan 2026
23 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 Upozorňujeme na zranitelnosti v Ruby-SAML, CVE-2025-66567 a CVE-2025-66568. Tyto zranitelnosti umožňují obejít validaci SAML assertion a tím pádem útočníkům umožňují vydávat se za legitimní uživatele bez platných přihlašovacích údajů. Problém vycház
@GOVCERT_CZ
10 Dec 2025
286 Impressions
1 Retweet
1 Like
0 Bookmarks
0 Replies
0 Quotes
🚨 SAML SIGN-IN HIJACK — CVE-2025-66568 in ruby-saml! Upgrade to 1.18.0+ NOW. This auth-bypass can let attackers sidestep SSO. If you can’t patch immediately: disable public SSO endpoints, rotate keys/sessions & audit logins. 🔍 https://t.co/Qkj7lulPSF #SAML #rubySAML
@vulert_official
9 Dec 2025
5 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-66568 The ruby-saml library implements the client side of an SAML authorization. Versions up to and including 1.12.4, are vulnerable to authentication bypass through the li… https://t.co/M0ui491rOp
@CVEnew
9 Dec 2025
26 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:onelogin:ruby-saml:*:*:*:*:*:*:*:*",
"matchCriteriaId": "16781771-8893-4189-B51B-66319E3B378C",
"versionEndExcluding": "1.18.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]