High severity7.5NVD Advisory· Published Mar 12, 2025· Updated Jun 17, 2026
CVE-2025-25293
CVE-2025-25293
Description
ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. Prior to versions 1.12.4 and 1.18.0, ruby-saml is susceptible to remote Denial of Service (DoS) with compressed SAML responses. ruby-saml uses zlib to decompress SAML responses in case they're compressed. It is possible to bypass the message size check with a compressed assertion since the message size is checked before inflation and not after. This issue may lead to remote Denial of Service (DoS). Versions 1.12.4 and 1.18.0 fix the issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
ruby-samlRubyGems | < 1.12.4 | 1.12.4 |
ruby-samlRubyGems | >= 1.13.0, < 1.18.0 | 1.18.0 |
Affected products
5- osv-coords2 versions
< 17.9.2+ 1 more
- (no CPE)range: < 17.9.2
- (no CPE)range: < 1.12.4
- Range: < 1.12.4
Patches
Vulnerability mechanics
References
15- about.gitlab.com/releases/2025/03/12/patch-release-gitlab-17-9-2-releasednvdPatchWEB
- github.com/SAML-Toolkits/ruby-saml/commit/acac9e9cc0b9a507882c614f25d41f8b47be349anvdPatchWEB
- github.com/SAML-Toolkits/ruby-saml/commit/e2da4c6dae7dc01a4d9cd221395140a67e2b3eb1nvdPatchWEB
- github.blog/security/sign-in-as-anyone-bypassing-saml-sso-authentication-with-parser-differentialsnvdExploitThird Party AdvisoryWEB
- securitylab.github.com/advisories/GHSL-2024-355_ruby-samlnvdExploitThird Party AdvisoryADVISORY
- github.com/SAML-Toolkits/ruby-saml/security/advisories/GHSA-92rq-c8cf-prrqnvdVendor AdvisoryWEB
- github.com/advisories/GHSA-92rq-c8cf-prrqghsaADVISORY
- github.com/omniauth/omniauth-saml/security/advisories/GHSA-hw46-3hmr-x9xvnvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2025-25293ghsaADVISORY
- security.netapp.com/advisory/ntap-20250314-0008/nvdThird Party Advisory
- github.com/SAML-Toolkits/ruby-saml/releases/tag/v1.12.4nvdRelease NotesWEB
- github.com/SAML-Toolkits/ruby-saml/releases/tag/v1.18.0nvdRelease NotesWEB
- github.com/rubysec/ruby-advisory-db/blob/master/gems/ruby-saml/CVE-2025-25293.ymlghsaWEB
- lists.debian.org/debian-lts-announce/2025/04/msg00011.htmlnvdWEB
- security.netapp.com/advisory/ntap-20250314-0008ghsaWEB
News mentions
0No linked articles in our index yet.