VendorsOmniAuthomniauth_samlall versions
Vulnerabilities

OmniAuth SAML

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2024-45409
The Ruby SAML library vulnerable to a SAML authentication bypass via Incorrect XPath selector
Published 2024-09-10 · Modified
10.0EPSS 0.107
CVE-2025-25292
Ruby SAML vulnerable to SAML authentication bypass due to namespace handling (parser differential)
Published 2025-03-12 · Modified
9.8EPSS 0.651
CVE-2025-25291
ruby-saml vulnerable to SAML authentication bypass due to DOCTYPE handling (parser differential)
Published 2025-03-12 · Modified
9.8EPSS 0.206
CVE-2017-11430
Multiple SAML libraries may allow authentication bypass via incorrect XML canonicalization and DOM traversal
Published 2019-04-17 · Modified
9.8EPSS 0.024
CVE-2025-25293
ruby-saml vulnerable to Remote Denial of Service (DoS) with compressed SAML responses
Published 2025-03-12 · Modified
7.7EPSS 0.015