logo

Ruby SAML Library Vulnerability Let Attackers Bypass Authentication

ID: e062e64b-0b19-53b6-876f-81d7ea802a8f

STIX ID: report--e062e64b-0b19-53b6-876f-81d7ea802a8f

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2025-12-09

Date Updated: 2026-04-21

Author: Abinaya

...
...

A critical CVE-2025-66567 vulnerability in the ruby-saml (RubyGems) library allows attackers to bypass SAML authentication via a Signature Wrapping attack caused by differing XML parser behavior (ReXML vs Nokogiri); it affects versions up to 1.12.4, has a CVSS of 10.0, can be exploited remotely with no user interaction, and organizations are advised to upgrade to ruby-saml 1.18.0 or later to mitigate the issue.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.