ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. Prior to versions 1.12.4 and 1.18.0, ruby-saml is susceptible to remote Denial of Service (DoS) with compressed SAML responses. ruby-saml uses zlib to decompress SAML responses in case they're compressed. It is possible to bypass the message size check with a compressed assertion since the message size is checked before inflation and not after. This issue may lead to remote Denial of Service (DoS). Versions 1.12.4 and 1.18.0 fix the issue.
Advisories
Source ID Title
Debian DLA Debian DLA DLA-4115-1 ruby-saml security update
EUVD EUVD EUVD-2025-6413 ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. Prior to versions 1.12.4 and 1.18.0, ruby-saml is susceptible to remote Denial of Service (DoS) with compressed SAML responses. ruby-saml uses zlib to decompress SAML responses in case they're compressed. It is possible to bypass the message size check with a compressed assertion since the message size is checked before inflation and not after. This issue may lead to remote Denial of Service (DoS). Versions 1.12.4 and 1.18.0 fix the issue.
Github GHSA Github GHSA GHSA-92rq-c8cf-prrq Ruby SAML allows remote Denial of Service (DoS) with compressed SAML responses
Ubuntu USN Ubuntu USN USN-7409-1 RubySAML vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 04 Nov 2025 05:30:00 +0900

Type Values Removed Values Added
References

Sat, 13 Sep 2025 04:15:00 +0900

Type Values Removed Values Added
References

Sat, 02 Aug 2025 00:00:00 +0900

Type Values Removed Values Added
First Time appeared Omniauth
Omniauth omniauth Saml
Onelogin
Onelogin ruby-saml
CPEs cpe:2.3:a:omniauth:omniauth_saml:*:*:*:*:*:ruby:*:*
cpe:2.3:a:onelogin:ruby-saml:*:*:*:*:*:*:*:*
Vendors & Products Omniauth
Omniauth omniauth Saml
Onelogin
Onelogin ruby-saml
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Sat, 12 Jul 2025 22:45:00 +0900

Type Values Removed Values Added
Metrics epss

{'score': 0.00179}

epss

{'score': 0.00271}


Fri, 14 Mar 2025 19:45:00 +0900

Type Values Removed Values Added
References

Thu, 13 Mar 2025 06:45:00 +0900

Type Values Removed Values Added
References
Metrics cvssV4_0

{'score': 6.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U'}

cvssV4_0

{'score': 7.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P'}


Thu, 13 Mar 2025 06:15:00 +0900

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Mar 2025 06:00:00 +0900


Thu, 13 Mar 2025 05:30:00 +0900

Type Values Removed Values Added
Description ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. Prior to versions 1.12.4 and 1.18.0, ruby-saml is susceptible to remote Denial of Service (DoS) with compressed SAML responses. ruby-saml uses zlib to decompress SAML responses in case they're compressed. It is possible to bypass the message size check with a compressed assertion since the message size is checked before inflation and not after. This issue may lead to remote Denial of Service (DoS). Versions 1.12.4 and 1.18.0 fix the issue.
Title ruby-saml vulnerable to Remote Denial of Service (DoS) with compressed SAML responses
Weaknesses CWE-400
References
Metrics cvssV4_0

{'score': 6.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-11-03T19:45:02.622Z

Reserved: 2025-02-06T17:13:33.122Z

Link: CVE-2025-25293

cve-icon Vulnrichment

Updated: 2025-03-14T10:03:12.372Z

cve-icon NVD

Status : Modified

Published: 2025-03-12T21:15:42.363

Modified: 2025-11-03T20:17:59.253

Link: CVE-2025-25293

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses