Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-25293

23
FAUCET Score

CVE-2025-25293 is a remote Denial of Service (DoS) vulnerability affecting ruby-saml versions prior to 1.12.4 and 1.18.0, as well as products like omniauth-saml and onelogin-saml that utilize it. The vulnerability stems from an insufficient message size check before decompression of SAML responses, allowing attackers to bypass the check with compressed assertions. This flaw carries a CVSS score of 7.5 (HIGH), indicating a network-based attack with low complexity, requiring no privileges or user interaction, and leading to high availability impact. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.10.6CPE matchmatch criteria
cpe:2.3:a:omniauth:omniauth_saml:*:*:*:*:*:ruby:*:*
>= 2.0.0, < 2.1.3CPE matchmatch criteria
cpe:2.3:a:omniauth:omniauth_saml:*:*:*:*:*:ruby:*:*
>= 2.2.0, < 2.2.3CPE matchmatch criteria
cpe:2.3:a:omniauth:omniauth_saml:*:*:*:*:*:ruby:*:*
< 1.12.4CPE matchmatch criteria
cpe:2.3:a:onelogin:ruby-saml:*:*:*:*:*:*:*:*
>= 1.13.0, < 1.18.0CPE matchmatch criteria
cpe:2.3:a:onelogin:ruby-saml:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

7.7HIGH

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
NONE
VS Integrity
NONE
VS Availability
HIGH
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
PROOF_OF_CONCEPT
CvssVersion
4.0

Exploit Intelligence

EPSS Score
1.36%
Probability of exploitation in next 30 days
EPSS Percentile
68.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0136 is in the 49th percentile among its peer group of 51,485 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

github_advisorypatch availablevia nvd_reference
View patch
rubygemspatch availablevia ghsa
Product: ruby-samlFixed in: 1.12.4
rubygemspatch availablevia ghsa
Product: ruby-samlFixed in: 1.18.0

Vendor Advisories (1)

rubygemsGHSA-92rq-c8cf-prrqhigh

Ruby SAML allows remote Denial of Service (DoS) with compressed SAML responses

Mar 12, 2025

References

lists.debian.org / debian-lts-announce/2025/04/msg00011.html
security.netapp.com / advisory/ntap-20250314-0008
Third Party Advisory
about.gitlab.com / releases/2025/03/12/patch-release-gitlab-17-9-2-released
Patch
github.blog / security/sign-in-as-anyone-bypassing-saml-sso-authentication-with-parser-differentials
ExploitThird Party Advisory
github.com / omniauth/omniauth-saml/security/advisories/GHSA-hw46-3hmr-x9xv
Vendor Advisory
github.com / SAML-Toolkits/ruby-saml/commit/acac9e9cc0b9a507882c614f25d41f8b47be349a
Patch
github.com / SAML-Toolkits/ruby-saml/commit/e2da4c6dae7dc01a4d9cd221395140a67e2b3eb1
Patch
github.com / SAML-Toolkits/ruby-saml/releases/tag/v1.12.4
Release Notes
github.com / SAML-Toolkits/ruby-saml/releases/tag/v1.18.0
Release Notes
github.com / SAML-Toolkits/ruby-saml/security/advisories/GHSA-92rq-c8cf-prrq
Vendor Advisory
securitylab.github.com / advisories/GHSL-2024-355_ruby-saml
ExploitThird Party Advisory