VendorsOneLoginruby-samlany version
Vulnerabilities

OneLogin Ruby-SAML any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2024-45409
The Ruby SAML library vulnerable to a SAML authentication bypass via Incorrect XPath selector
Published 2024-09-10 · Modified
10.0EPSS 0.107
CVE-2025-25292
Ruby SAML vulnerable to SAML authentication bypass due to namespace handling (parser differential)
Published 2025-03-12 · Modified
9.8EPSS 0.651
CVE-2025-25291
ruby-saml vulnerable to SAML authentication bypass due to DOCTYPE handling (parser differential)
Published 2025-03-12 · Modified
9.8EPSS 0.206
CVE-2017-11428
Multiple SAML libraries may allow authentication bypass via incorrect XML canonicalization and DOM traversal
Published 2019-04-17 · Modified
9.8EPSS 0.024
CVE-2015-20108
xml_security.rb in the ruby-saml gem before 1.0.0 for Ruby allows XPath injection and code execution because prepared statements are not used.
Published 2023-05-27 · Modified
9.8EPSS 0.013
CVE-2025-66567
ruby-saml has a SAML authentication bypass due to namespace handling (parser differential)
Published 2025-12-09 · Analyzed
9.3EPSS 0.004
CVE-2025-66568
ruby-saml Libxml2 Canonicalization errors can bypass Digest/Signature validation
Published 2025-12-09 · Analyzed
9.3EPSS 0.002
CVE-2025-25293
ruby-saml vulnerable to Remote Denial of Service (DoS) with compressed SAML responses
Published 2025-03-12 · Modified
7.7EPSS 0.015
CVE-2016-5697
Ruby-saml before 1.3.0 allows attackers to perform XML signature wrapping attacks via unspecified vectors.
Published 2017-01-23 · Modified
7.5EPSS 0.012