CVE-2025-25292 is an authentication bypass vulnerability in ruby-saml, affecting versions prior to 1.12.4 and 1.18.0, and consequently impacting products like NetApp, OmniAuth, and OneLogin offerings that utilize ruby-saml. This critical vulnerability (CVSS 9.8) stems from a parser differential between REXML and Nokogiri, enabling Signature Wrapping attacks that can lead to complete authentication bypass. While there is no evidence of active exploitation in the wild, the vulnerability has garnered significant community discussion and media coverage, with a public demonstration of its impact on high-profile projects like GitLab. No public exploit code (Metasploit, Nuclei, ExploitDB) is currently available, and it is not listed on the CISA KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.10.6CPE matchmatch criteria | cpe:2.3:a:omniauth:omniauth_saml:*:*:*:*:*:ruby:*:* | ||
>= 2.0.0, < 2.1.3CPE matchmatch criteria | cpe:2.3:a:omniauth:omniauth_saml:*:*:*:*:*:ruby:*:* | ||
>= 2.2.0, < 2.2.3CPE matchmatch criteria | cpe:2.3:a:omniauth:omniauth_saml:*:*:*:*:*:ruby:*:* | ||
< 1.12.4CPE matchmatch criteria | cpe:2.3:a:onelogin:ruby-saml:*:*:*:*:*:*:*:* | ||
>= 1.13.0, < 1.18.0CPE matchmatch criteria | cpe:2.3:a:onelogin:ruby-saml:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.