CVE-2025-25293
ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. Prior to versions 1.12.4 and 1.18.0, ruby-saml is susceptible to remote Denial of Service (DoS) with compressed SAML responses. ruby-saml uses zlib to decompress SAML responses in case they're compressed. It is possible to bypass the message size check with a compressed assertion since the message size is checked before inflation and not after. This issue may lead to remote Denial of Service (DoS). Versions 1.12.4 and 1.18.0 fix the issue.
- Omniauth Omniauth Saml
- < 1.10.6, 2.1.3, 2.2.3
- Onelogin Ruby-saml
- < 1.12.4, 1.18.0
- Fix
- Available
- CVSS 4.0
- 8.7 HIGH
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 1.5% (72th percentile)
- Weakness
- CWE-400
- NVD status
- Modified
- Published
- 2025-03-12
CVE-2025-25293 at NVD
1 known exploit for CVE-2025-25293
Proof-of-concept code and exploit modules indexed by Sploitus