Ruby Saml
Vendor:
First CVE: Jan 23, 2017 · Active for 9 years
9
Total CVEs
More Total CVEs than 86% of tracked products
1.8
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
9.1
Avg CVSS
Higher Avg CVSS than 85% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Ruby Saml over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 23, 2017
9 years ago
Most Recent CVE
Dec 9, 2025
227 days ago
CVE Severity & Scoring
Ruby Saml9 CVEs
22%
78%
All CVEs352,231 CVEs
45%
40%
11%
HighCritical
Attack Vector
Local0 (0.0%)
Network9 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None9 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None9 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-25292CRITICAL ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. An authentication bypass vulnerability was found in ruby-saml prior to versions 1.12.4 a | Mar 12, 2025 | 9.8 | 67 | NO | NO |
CVE-2025-25291CRITICAL ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. An authentication bypass vulnerability was found in ruby-saml prior to versions 1.12.4 a | Mar 12, 2025 | 9.8 | 53 | NO | YES |
CVE-2024-45409CRITICAL The Ruby SAML library is for implementing the client side of a SAML authorization. Ruby-SAML in <= 12.2 and 1.13.0 <= 1.16.0 does not properly verify the signature of the SAML Resp | Sep 10, 2024 | 9.8 | 52 | NO | YES |
CVE-2025-66568CRITICAL The ruby-saml library implements the client side of an SAML authorization. Versions up to and including 1.12.4, are vulnerable to authentication bypass through the libxml2 canonica | Dec 9, 2025 | 9.1 | 31 | NO | NO |
CVE-2025-66567CRITICAL The ruby-saml library is for implementing the client side of a SAML authorization. ruby-saml versions up to and including 1.12.4 contain an authentication bypass vulnerability due | Dec 9, 2025 | 9.1 | 31 | NO | NO |
CVE-2015-20108CRITICAL xml_security.rb in the ruby-saml gem before 1.0.0 for Ruby allows XPath injection and code execution because prepared statements are not used. | May 27, 2023 | 9.8 | 30 | NO | NO |
CVE-2017-11428CRITICAL OneLogin Ruby-SAML 1.6.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the | Apr 17, 2019 | 9.8 | 25 | NO | NO |
CVE-2025-25293HIGH ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. Prior to versions 1.12.4 and 1.18.0, ruby-saml is susceptible to remote Denial of Servic | Mar 12, 2025 | 7.5 | 23 | NO | NO |
CVE-2016-5697HIGH Ruby-saml before 1.3.0 allows attackers to perform XML signature wrapping attacks via unspecified vectors. | Jan 23, 2017 | 7.5 | 19 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (9 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
22.2% of CVEs· 98th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (9 CVEs).
Media Mentions
Signals from CVEs in this product scope (9 CVEs).
Top CNAs Publishing CVEs For Ruby Saml
Top CWEs
Versions
No cataloged versions.