Skip to content

Signature Wrapping Attack issue on ruby-saml

Critical
bufferoverflow published GHSA-hw46-3hmr-x9xv Mar 12, 2025

Package

bundler omniauth-saml (RubyGems)

Affected versions

<2.2.2, <1.10.5

Patched versions

2.2.3, 2.1.3, 1.10.6

Description

Summary

There are 2 new Critical Signature Wrapping Vulnerabilities (CVE-2025-25292, CVE-2025-25291) and a potential DDOS Moderated Vulneratiblity (CVE-2025-25293) affecting ruby-saml, a dependency of omniauth-saml.

The fix gonna be applied to ruby-saml and released tomorrow 12 Mar, under v1.18.0 version.

Please upgrade the ruby-saml requirement to v1.18.0

Impact

Signature Wrapping Vulnerabilities allows an attacker to impersonate a user.

Severity

Critical

CVE ID

No known CVE

Weaknesses