Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Omniauth

First CVE: Jan 26, 2018Active for: 8 yearsTotal CVEs: 8

Omniauth is a focused authentication middleware library that centralizes federated login across web applications, despite its narrow product scope occupying a prominent role in the Ruby and web-application ecosystem as a widely adopted single sign-on abstraction layer. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, concentrating in its core SAML and general authentication products through recurring weakness classes including improper cryptographic-signature verification, authentication bypass, CSRF, and output-encoding flaws that strike at the trust and integrity mechanisms essential to federated identity. Defenders should treat Omniauth advisories as high-priority for any application relying on federated authentication; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
8
Total CVEs
More Total CVEs than 90% of tracked vendors
0.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
9.1
Avg CVSS Score
Higher Avg CVSS Score than 88% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Omniauth over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 26, 2018
8 years ago
Most Recent CVE
Mar 12, 2025
499 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (8 CVEs).

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-25292CRITICAL
ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. An authentication bypass vulnerability was found in ruby-saml prior to versions 1.12.4 a
Mar 12, 20259.867NONO
CVE-2025-25291CRITICAL
ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. An authentication bypass vulnerability was found in ruby-saml prior to versions 1.12.4 a
Mar 12, 20259.853NOYES
CVE-2024-45409CRITICAL
The Ruby SAML library is for implementing the client side of a SAML authorization. Ruby-SAML in <= 12.2 and 1.13.0 <= 1.16.0 does not properly verify the signature of the SAML Resp
Sep 10, 20249.852NOYES
CVE-2020-36599CRITICAL
lib/omniauth/failure_endpoint.rb in OmniAuth before 1.9.2 (and before 2.0) does not escape the message_key value.
Aug 18, 20229.831NONO
CVE-2017-11430CRITICAL
OmniAuth OmnitAuth-SAML 1.9.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulat
Apr 17, 20199.830NONO
CVE-2015-9284HIGH
The request phase of the OmniAuth Ruby gem (1.9.1 and earlier) is vulnerable to Cross-Site Request Forgery when used as part of the Ruby on Rails framework, allowing accounts to be
Apr 26, 20198.826NONO
CVE-2017-18076HIGH
In strategy.rb in OmniAuth before 1.3.2, the authenticity_token value is improperly protected because POST (in addition to GET) parameters are stored in the session and become avai
Jan 26, 20187.525NONO
CVE-2025-25293HIGH
ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. Prior to versions 1.12.4 and 1.18.0, ruby-saml is susceptible to remote Denial of Servic
Mar 12, 20257.523NONO
View all 8 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products8 CVEs
38%
63%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
HighCritical
Attack Vector
Local0 (0.0%)
Network8 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None7 (87.5%)
Unknown0 (0.0%)
Required1 (12.5%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None8 (100.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (8 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
25.0% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Omniauth.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Omniauth — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Omniauth's Products

View all 4 CNAs →

Top CWEs