GHSA-x4h9-gwv3-r4m4
CRITICALCVE-2025-66568Ruby-saml up to and including 1.12.4, there is an authentication bypass vulnerability because of an issue at libxml2 canonicalization process used by Nokogiri for document transformation. That allows an attacker to be able to execute a Signature Wrapping attack. The vulnerability does not affect the version 1.18.0.
- Affected
- < 1.18.0
- Fixed in
- 1.18.0
- Weakness
- CWE-347
- Published
- 2025-12-08
- Source
- github