Ruby SAML Library Vulnerability Let Attackers Bypass Authentication
ID: e062e64b-0b19-53b6-876f-81d7ea802a8f
STIX ID: report--e062e64b-0b19-53b6-876f-81d7ea802a8f
Feed Name: cybersecurityNews.com
Threat Score
A critical CVE-2025-66567 vulnerability in the ruby-saml (RubyGems) library allows attackers to bypass SAML authentication via a Signature Wrapping attack caused by differing XML parser behavior (ReXML vs Nokogiri); it affects versions up to 1.12.4, has a CVSS of 10.0, can be exploited remotely with no user interaction, and organizations are advised to upgrade to ruby-saml 1.18.0 or later to mitigate the issue.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
