CRITICAL10.0CVE-2024-45409The Ruby SAML library vulnerable to a SAML authentication bypass via Incorrect XPath selector from 0, < 1.12.3
CRITICAL9.8CVE-2025-25292Ruby SAML vulnerable to SAML authentication bypass due to namespace handling (parser differential) >= 1.13.0, < 1.18.0
CRITICAL9.8CVE-2025-25291ruby-saml vulnerable to SAML authentication bypass due to DOCTYPE handling (parser differential) from 0, < 1.12.4
CRITICAL9.8ruby-saml vulnerable to XPath injection
from 0, < 1.0.0
HIGH7.7Ruby-SAML Improper Authentication vulnerability
from 0, < 1.7.0
HIGH7.5ruby-saml vulnerable to Remote Denial of Service (DoS) with compressed SAML responses
from 0, < 1.12.4
HIGH7.5Ruby-saml allows attackers to perform XML signature wrapping attacks
from 0, < 1.3.0
—Ruby-saml allows a Libxml2 Canonicalization error to bypass Digest/Signature validation
from 0, < 1.18.0
—Ruby-saml has a SAML authentication bypass due to namespace handling (parser differential)
from 0, < 1.18.0
—ruby-saml - security update
from 0, < 1.18.1