CVE-2025-25292 - CVE House
Back to Database
Status published Critical CVE-2025-25292

Ruby SAML vulnerable to SAML authentication bypass due to namespace handling (parser differential)

Vulnerability Description

ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. An authentication bypass vulnerability was found in ruby-saml prior to versions 1.12.4 and 1.18.0 due to a parser differential. ReXML and Nokogiri parse XML differently, the parsers can generate entirely different document structures from the same XML input. That allows an attacker to be able to execute a Signature Wrapping attack. This issue may lead to authentication bypass. Versions 1.12.4 and 1.18.0 contain a patch for the issue.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-25292

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

SAML-Toolkits

View all reports →

Affected Software

ruby-saml
Vulnerable Versions:
< 1.12.4, >= 1.13.0, < 1.18.0

Timeline

Official Publish: March 12th, 2025
Last Modified: November 3rd, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)