Skip to content

IMPORTANT: All users must upgrade to ruby-saml 1.18.0 ASAP #753

@pitbulk

Description

@pitbulk

It fixes several vulnerabilities:

Fix vulnerabilities: CVE-2025-25291, CVE-2025-25292: SAML authentication bypass via Signature Wrapping attack allowed due parser differential.

Fix vulnerability: CVE-2025-25293: Potential DOS abusing of compressed messages.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions