Omniauth is a focused authentication middleware library that centralizes federated login across web applications, despite its narrow product scope occupying a prominent role in the Ruby and web-application ecosystem as a widely adopted single sign-on abstraction layer. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, concentrating in its core SAML and general authentication products through recurring weakness classes including improper cryptographic-signature verification, authentication bypass, CSRF, and output-encoding flaws that strike at the trust and integrity mechanisms essential to federated identity. Defenders should treat Omniauth advisories as high-priority for any application relying on federated authentication; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Omniauth over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-25292CRITICAL ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. An authentication bypass vulnerability was found in ruby-saml prior to versions 1.12.4 a | Mar 12, 2025 | 9.8 | 67 | NO | NO |
CVE-2025-25291CRITICAL ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. An authentication bypass vulnerability was found in ruby-saml prior to versions 1.12.4 a | Mar 12, 2025 | 9.8 | 53 | NO | YES |
CVE-2024-45409CRITICAL The Ruby SAML library is for implementing the client side of a SAML authorization. Ruby-SAML in <= 12.2 and 1.13.0 <= 1.16.0 does not properly verify the signature of the SAML Resp | Sep 10, 2024 | 9.8 | 52 | NO | YES |
CVE-2020-36599CRITICAL lib/omniauth/failure_endpoint.rb in OmniAuth before 1.9.2 (and before 2.0) does not escape the message_key value. | Aug 18, 2022 | 9.8 | 31 | NO | NO |
CVE-2017-11430CRITICAL OmniAuth OmnitAuth-SAML 1.9.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulat | Apr 17, 2019 | 9.8 | 30 | NO | NO |
CVE-2015-9284HIGH The request phase of the OmniAuth Ruby gem (1.9.1 and earlier) is vulnerable to Cross-Site Request Forgery when used as part of the Ruby on Rails framework, allowing accounts to be | Apr 26, 2019 | 8.8 | 26 | NO | NO |
CVE-2017-18076HIGH In strategy.rb in OmniAuth before 1.3.2, the authenticity_token value is improperly protected because POST (in addition to GET) parameters are stored in the session and become avai | Jan 26, 2018 | 7.5 | 25 | NO | NO |
CVE-2025-25293HIGH ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. Prior to versions 1.12.4 and 1.18.0, ruby-saml is susceptible to remote Denial of Servic | Mar 12, 2025 | 7.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Omniauth.
Media articles that mention a CVE ID that affects a product developed by Omniauth — matched by CVE ID, not by vendor name.