omniauth-saml
A generic SAML strategy for OmniAuth.
Activity
- Latest release
- 6mo ago
- Total releases
- 35
- Cadence
- ~3 months
- Last 12 months
- 1
Reach
- Stars
- —
Details
- License
- MIT
- First release
- Feb 14, 2012
| Version | Released | |
|---|---|---|
2.2.5
patch
|
2.2.5
patch
Dependencies (8)
Changelog
Compare changes
|
|
2.2.4
patch
|
2.2.4
patch
Dependencies (8)
Changelog
Compare changes
|
|
2.1.3
patch
|
2.1.3
patch
Dependencies (8)
Changelog
Compare changes
|
|
1.10.6
patch
|
1.10.6
patch
Dependencies (8)
Changelog
Compare changes
|
|
2.2.3
patch
|
2.2.3
patch
Dependencies (8)
Changelog
Compare changes
|
|
2.2.2
patch
1 CVE
GHSA-hw46-3hmr-x9xv
Mar 12, 2025
omniauth-saml has dependency on ruby-saml version with Signature Wrapping Attack issue
Critical
SummaryThere are 2 new Critical Signature Wrapping Vulnerabilities (CVE-2025-25292, CVE-2025-25291) and a potential DDOS Moderated Vulneratiblity (CVE-2025-25293) affecting ruby-saml, a dependency of omniauth-saml. The fix will be applied to ruby-saml and released 12 March 2025, under version 1.18.0. Please upgrade the ruby-saml requirement to v1.18.0. ImpactSignature Wrapping Vulnerabilities allows an attacker to impersonate a user. Affected versions
2.2.0
2.2.1
2.2.2
2.0.0
2.1.0
2.1.1
2.1.2
0.9.0
0.9.1
0.9.2
1.0.0
1.1.0
+ 18 more Show less
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.10.6
2.1.3
2.2.3
References
Updated Feb 04, 2026 · Source: OSV.dev |
2.2.2
patch
Dependencies (8)
Changelog
Compare changes
|
|
1.10.5
patch
1 CVE
GHSA-hw46-3hmr-x9xv
Mar 12, 2025
omniauth-saml has dependency on ruby-saml version with Signature Wrapping Attack issue
Critical
SummaryThere are 2 new Critical Signature Wrapping Vulnerabilities (CVE-2025-25292, CVE-2025-25291) and a potential DDOS Moderated Vulneratiblity (CVE-2025-25293) affecting ruby-saml, a dependency of omniauth-saml. The fix will be applied to ruby-saml and released 12 March 2025, under version 1.18.0. Please upgrade the ruby-saml requirement to v1.18.0. ImpactSignature Wrapping Vulnerabilities allows an attacker to impersonate a user. Affected versions
2.2.0
2.2.1
2.2.2
2.0.0
2.1.0
2.1.1
2.1.2
0.9.0
0.9.1
0.9.2
1.0.0
1.1.0
+ 18 more Show less
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.10.6
2.1.3
2.2.3
References
Updated Feb 04, 2026 · Source: OSV.dev |
1.10.5
patch
Dependencies (8)
Changelog
Compare changes
|
|
1.10.4
patch
2 CVEs
GHSA-hw46-3hmr-x9xv
Mar 12, 2025
omniauth-saml has dependency on ruby-saml version with Signature Wrapping Attack issue
Critical
SummaryThere are 2 new Critical Signature Wrapping Vulnerabilities (CVE-2025-25292, CVE-2025-25291) and a potential DDOS Moderated Vulneratiblity (CVE-2025-25293) affecting ruby-saml, a dependency of omniauth-saml. The fix will be applied to ruby-saml and released 12 March 2025, under version 1.18.0. Please upgrade the ruby-saml requirement to v1.18.0. ImpactSignature Wrapping Vulnerabilities allows an attacker to impersonate a user. Affected versions
2.2.0
2.2.1
2.2.2
2.0.0
2.1.0
2.1.1
2.1.2
0.9.0
0.9.1
0.9.2
1.0.0
1.1.0
+ 18 more Show less
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.10.6
2.1.3
2.2.3
References
Updated Feb 04, 2026 · Source: OSV.dev
GHSA-cvp8-5r8g-fhvq
Sep 11, 2024
omniauth-saml vulnerable to Improper Verification of Cryptographic Signature
Critical
Network
Low
None
None
ruby-saml, the dependent SAML gem of omniauth-saml has a signature wrapping vulnerability in <= v1.12.0 and v1.13.0 to v1.16.0 , see https://github.com/SAML-Toolkits/ruby-saml/security/advisories/GHSA-jw9c-mfg7-9rx2 As a result, omniauth-saml created a new release by upgrading ruby-saml to the patched versions v1.17. Affected versions
2.0.0
2.1.0
2.1.1
0.9.0
0.9.1
0.9.2
1.0.0
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
+ 14 more Show less
1.10.4
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
2.2.0
Fixed in
1.10.5
2.1.2
2.2.1
References
Updated Aug 07, 2026 · Source: OSV.dev |
1.10.4
patch
Dependencies (8)
Changelog
Compare changes
|
|
2.1.2
patch
1 CVE
GHSA-hw46-3hmr-x9xv
Mar 12, 2025
omniauth-saml has dependency on ruby-saml version with Signature Wrapping Attack issue
Critical
SummaryThere are 2 new Critical Signature Wrapping Vulnerabilities (CVE-2025-25292, CVE-2025-25291) and a potential DDOS Moderated Vulneratiblity (CVE-2025-25293) affecting ruby-saml, a dependency of omniauth-saml. The fix will be applied to ruby-saml and released 12 March 2025, under version 1.18.0. Please upgrade the ruby-saml requirement to v1.18.0. ImpactSignature Wrapping Vulnerabilities allows an attacker to impersonate a user. Affected versions
2.2.0
2.2.1
2.2.2
2.0.0
2.1.0
2.1.1
2.1.2
0.9.0
0.9.1
0.9.2
1.0.0
1.1.0
+ 18 more Show less
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.10.6
2.1.3
2.2.3
References
Updated Feb 04, 2026 · Source: OSV.dev |
2.1.2
patch
Dependencies (8)
Changelog
Compare changes
|
|
2.2.1
patch
1 CVE
GHSA-hw46-3hmr-x9xv
Mar 12, 2025
omniauth-saml has dependency on ruby-saml version with Signature Wrapping Attack issue
Critical
SummaryThere are 2 new Critical Signature Wrapping Vulnerabilities (CVE-2025-25292, CVE-2025-25291) and a potential DDOS Moderated Vulneratiblity (CVE-2025-25293) affecting ruby-saml, a dependency of omniauth-saml. The fix will be applied to ruby-saml and released 12 March 2025, under version 1.18.0. Please upgrade the ruby-saml requirement to v1.18.0. ImpactSignature Wrapping Vulnerabilities allows an attacker to impersonate a user. Affected versions
2.2.0
2.2.1
2.2.2
2.0.0
2.1.0
2.1.1
2.1.2
0.9.0
0.9.1
0.9.2
1.0.0
1.1.0
+ 18 more Show less
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.10.6
2.1.3
2.2.3
References
Updated Feb 04, 2026 · Source: OSV.dev |
2.2.1
patch
Dependencies (8)
Changelog
Compare changes
|
|
2.1.1
patch
2 CVEs
GHSA-hw46-3hmr-x9xv
Mar 12, 2025
omniauth-saml has dependency on ruby-saml version with Signature Wrapping Attack issue
Critical
SummaryThere are 2 new Critical Signature Wrapping Vulnerabilities (CVE-2025-25292, CVE-2025-25291) and a potential DDOS Moderated Vulneratiblity (CVE-2025-25293) affecting ruby-saml, a dependency of omniauth-saml. The fix will be applied to ruby-saml and released 12 March 2025, under version 1.18.0. Please upgrade the ruby-saml requirement to v1.18.0. ImpactSignature Wrapping Vulnerabilities allows an attacker to impersonate a user. Affected versions
2.2.0
2.2.1
2.2.2
2.0.0
2.1.0
2.1.1
2.1.2
0.9.0
0.9.1
0.9.2
1.0.0
1.1.0
+ 18 more Show less
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.10.6
2.1.3
2.2.3
References
Updated Feb 04, 2026 · Source: OSV.dev
GHSA-cvp8-5r8g-fhvq
Sep 11, 2024
omniauth-saml vulnerable to Improper Verification of Cryptographic Signature
Critical
Network
Low
None
None
ruby-saml, the dependent SAML gem of omniauth-saml has a signature wrapping vulnerability in <= v1.12.0 and v1.13.0 to v1.16.0 , see https://github.com/SAML-Toolkits/ruby-saml/security/advisories/GHSA-jw9c-mfg7-9rx2 As a result, omniauth-saml created a new release by upgrading ruby-saml to the patched versions v1.17. Affected versions
2.0.0
2.1.0
2.1.1
0.9.0
0.9.1
0.9.2
1.0.0
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
+ 14 more Show less
1.10.4
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
2.2.0
Fixed in
1.10.5
2.1.2
2.2.1
References
Updated Aug 07, 2026 · Source: OSV.dev |
2.1.1
patch
Dependencies (8)
Changelog
Compare changes
|
|
2.2.0
minor
2 CVEs
GHSA-hw46-3hmr-x9xv
Mar 12, 2025
omniauth-saml has dependency on ruby-saml version with Signature Wrapping Attack issue
Critical
SummaryThere are 2 new Critical Signature Wrapping Vulnerabilities (CVE-2025-25292, CVE-2025-25291) and a potential DDOS Moderated Vulneratiblity (CVE-2025-25293) affecting ruby-saml, a dependency of omniauth-saml. The fix will be applied to ruby-saml and released 12 March 2025, under version 1.18.0. Please upgrade the ruby-saml requirement to v1.18.0. ImpactSignature Wrapping Vulnerabilities allows an attacker to impersonate a user. Affected versions
2.2.0
2.2.1
2.2.2
2.0.0
2.1.0
2.1.1
2.1.2
0.9.0
0.9.1
0.9.2
1.0.0
1.1.0
+ 18 more Show less
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.10.6
2.1.3
2.2.3
References
Updated Feb 04, 2026 · Source: OSV.dev
GHSA-cvp8-5r8g-fhvq
Sep 11, 2024
omniauth-saml vulnerable to Improper Verification of Cryptographic Signature
Critical
Network
Low
None
None
ruby-saml, the dependent SAML gem of omniauth-saml has a signature wrapping vulnerability in <= v1.12.0 and v1.13.0 to v1.16.0 , see https://github.com/SAML-Toolkits/ruby-saml/security/advisories/GHSA-jw9c-mfg7-9rx2 As a result, omniauth-saml created a new release by upgrading ruby-saml to the patched versions v1.17. Affected versions
2.0.0
2.1.0
2.1.1
0.9.0
0.9.1
0.9.2
1.0.0
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
+ 14 more Show less
1.10.4
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
2.2.0
Fixed in
1.10.5
2.1.2
2.2.1
References
Updated Aug 07, 2026 · Source: OSV.dev |
2.2.0
minor
Dependencies (8)
Changelog
Compare changes
|
|
2.1.0
minor
2 CVEs
GHSA-hw46-3hmr-x9xv
Mar 12, 2025
omniauth-saml has dependency on ruby-saml version with Signature Wrapping Attack issue
Critical
SummaryThere are 2 new Critical Signature Wrapping Vulnerabilities (CVE-2025-25292, CVE-2025-25291) and a potential DDOS Moderated Vulneratiblity (CVE-2025-25293) affecting ruby-saml, a dependency of omniauth-saml. The fix will be applied to ruby-saml and released 12 March 2025, under version 1.18.0. Please upgrade the ruby-saml requirement to v1.18.0. ImpactSignature Wrapping Vulnerabilities allows an attacker to impersonate a user. Affected versions
2.2.0
2.2.1
2.2.2
2.0.0
2.1.0
2.1.1
2.1.2
0.9.0
0.9.1
0.9.2
1.0.0
1.1.0
+ 18 more Show less
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.10.6
2.1.3
2.2.3
References
Updated Feb 04, 2026 · Source: OSV.dev
GHSA-cvp8-5r8g-fhvq
Sep 11, 2024
omniauth-saml vulnerable to Improper Verification of Cryptographic Signature
Critical
Network
Low
None
None
ruby-saml, the dependent SAML gem of omniauth-saml has a signature wrapping vulnerability in <= v1.12.0 and v1.13.0 to v1.16.0 , see https://github.com/SAML-Toolkits/ruby-saml/security/advisories/GHSA-jw9c-mfg7-9rx2 As a result, omniauth-saml created a new release by upgrading ruby-saml to the patched versions v1.17. Affected versions
2.0.0
2.1.0
2.1.1
0.9.0
0.9.1
0.9.2
1.0.0
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
+ 14 more Show less
1.10.4
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
2.2.0
Fixed in
1.10.5
2.1.2
2.2.1
References
Updated Aug 07, 2026 · Source: OSV.dev |
2.1.0
minor
Dependencies (8)
Changelog
Compare changes
|
|
2.0.0
major
2 CVEs
GHSA-hw46-3hmr-x9xv
Mar 12, 2025
omniauth-saml has dependency on ruby-saml version with Signature Wrapping Attack issue
Critical
SummaryThere are 2 new Critical Signature Wrapping Vulnerabilities (CVE-2025-25292, CVE-2025-25291) and a potential DDOS Moderated Vulneratiblity (CVE-2025-25293) affecting ruby-saml, a dependency of omniauth-saml. The fix will be applied to ruby-saml and released 12 March 2025, under version 1.18.0. Please upgrade the ruby-saml requirement to v1.18.0. ImpactSignature Wrapping Vulnerabilities allows an attacker to impersonate a user. Affected versions
2.2.0
2.2.1
2.2.2
2.0.0
2.1.0
2.1.1
2.1.2
0.9.0
0.9.1
0.9.2
1.0.0
1.1.0
+ 18 more Show less
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.10.6
2.1.3
2.2.3
References
Updated Feb 04, 2026 · Source: OSV.dev
GHSA-cvp8-5r8g-fhvq
Sep 11, 2024
omniauth-saml vulnerable to Improper Verification of Cryptographic Signature
Critical
Network
Low
None
None
ruby-saml, the dependent SAML gem of omniauth-saml has a signature wrapping vulnerability in <= v1.12.0 and v1.13.0 to v1.16.0 , see https://github.com/SAML-Toolkits/ruby-saml/security/advisories/GHSA-jw9c-mfg7-9rx2 As a result, omniauth-saml created a new release by upgrading ruby-saml to the patched versions v1.17. Affected versions
2.0.0
2.1.0
2.1.1
0.9.0
0.9.1
0.9.2
1.0.0
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
+ 14 more Show less
1.10.4
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
2.2.0
Fixed in
1.10.5
2.1.2
2.2.1
References
Updated Aug 07, 2026 · Source: OSV.dev |
2.0.0
major
Dependencies (8)
Changelog
Compare changes
|
|
1.10.3
patch
2 CVEs
GHSA-hw46-3hmr-x9xv
Mar 12, 2025
omniauth-saml has dependency on ruby-saml version with Signature Wrapping Attack issue
Critical
SummaryThere are 2 new Critical Signature Wrapping Vulnerabilities (CVE-2025-25292, CVE-2025-25291) and a potential DDOS Moderated Vulneratiblity (CVE-2025-25293) affecting ruby-saml, a dependency of omniauth-saml. The fix will be applied to ruby-saml and released 12 March 2025, under version 1.18.0. Please upgrade the ruby-saml requirement to v1.18.0. ImpactSignature Wrapping Vulnerabilities allows an attacker to impersonate a user. Affected versions
2.2.0
2.2.1
2.2.2
2.0.0
2.1.0
2.1.1
2.1.2
0.9.0
0.9.1
0.9.2
1.0.0
1.1.0
+ 18 more Show less
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.10.6
2.1.3
2.2.3
References
Updated Feb 04, 2026 · Source: OSV.dev
GHSA-cvp8-5r8g-fhvq
Sep 11, 2024
omniauth-saml vulnerable to Improper Verification of Cryptographic Signature
Critical
Network
Low
None
None
ruby-saml, the dependent SAML gem of omniauth-saml has a signature wrapping vulnerability in <= v1.12.0 and v1.13.0 to v1.16.0 , see https://github.com/SAML-Toolkits/ruby-saml/security/advisories/GHSA-jw9c-mfg7-9rx2 As a result, omniauth-saml created a new release by upgrading ruby-saml to the patched versions v1.17. Affected versions
2.0.0
2.1.0
2.1.1
0.9.0
0.9.1
0.9.2
1.0.0
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
+ 14 more Show less
1.10.4
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
2.2.0
Fixed in
1.10.5
2.1.2
2.2.1
References
Updated Aug 07, 2026 · Source: OSV.dev |
1.10.3
patch
Dependencies (8)
Changelog
Compare changes
|
|
1.10.2
patch
2 CVEs
GHSA-hw46-3hmr-x9xv
Mar 12, 2025
omniauth-saml has dependency on ruby-saml version with Signature Wrapping Attack issue
Critical
SummaryThere are 2 new Critical Signature Wrapping Vulnerabilities (CVE-2025-25292, CVE-2025-25291) and a potential DDOS Moderated Vulneratiblity (CVE-2025-25293) affecting ruby-saml, a dependency of omniauth-saml. The fix will be applied to ruby-saml and released 12 March 2025, under version 1.18.0. Please upgrade the ruby-saml requirement to v1.18.0. ImpactSignature Wrapping Vulnerabilities allows an attacker to impersonate a user. Affected versions
2.2.0
2.2.1
2.2.2
2.0.0
2.1.0
2.1.1
2.1.2
0.9.0
0.9.1
0.9.2
1.0.0
1.1.0
+ 18 more Show less
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.10.6
2.1.3
2.2.3
References
Updated Feb 04, 2026 · Source: OSV.dev
GHSA-cvp8-5r8g-fhvq
Sep 11, 2024
omniauth-saml vulnerable to Improper Verification of Cryptographic Signature
Critical
Network
Low
None
None
ruby-saml, the dependent SAML gem of omniauth-saml has a signature wrapping vulnerability in <= v1.12.0 and v1.13.0 to v1.16.0 , see https://github.com/SAML-Toolkits/ruby-saml/security/advisories/GHSA-jw9c-mfg7-9rx2 As a result, omniauth-saml created a new release by upgrading ruby-saml to the patched versions v1.17. Affected versions
2.0.0
2.1.0
2.1.1
0.9.0
0.9.1
0.9.2
1.0.0
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
+ 14 more Show less
1.10.4
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
2.2.0
Fixed in
1.10.5
2.1.2
2.2.1
References
Updated Aug 07, 2026 · Source: OSV.dev |
1.10.2
patch
Dependencies (8)
Changelog
Compare changes
|
|
1.10.1
patch
2 CVEs
GHSA-hw46-3hmr-x9xv
Mar 12, 2025
omniauth-saml has dependency on ruby-saml version with Signature Wrapping Attack issue
Critical
SummaryThere are 2 new Critical Signature Wrapping Vulnerabilities (CVE-2025-25292, CVE-2025-25291) and a potential DDOS Moderated Vulneratiblity (CVE-2025-25293) affecting ruby-saml, a dependency of omniauth-saml. The fix will be applied to ruby-saml and released 12 March 2025, under version 1.18.0. Please upgrade the ruby-saml requirement to v1.18.0. ImpactSignature Wrapping Vulnerabilities allows an attacker to impersonate a user. Affected versions
2.2.0
2.2.1
2.2.2
2.0.0
2.1.0
2.1.1
2.1.2
0.9.0
0.9.1
0.9.2
1.0.0
1.1.0
+ 18 more Show less
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.10.6
2.1.3
2.2.3
References
Updated Feb 04, 2026 · Source: OSV.dev
GHSA-cvp8-5r8g-fhvq
Sep 11, 2024
omniauth-saml vulnerable to Improper Verification of Cryptographic Signature
Critical
Network
Low
None
None
ruby-saml, the dependent SAML gem of omniauth-saml has a signature wrapping vulnerability in <= v1.12.0 and v1.13.0 to v1.16.0 , see https://github.com/SAML-Toolkits/ruby-saml/security/advisories/GHSA-jw9c-mfg7-9rx2 As a result, omniauth-saml created a new release by upgrading ruby-saml to the patched versions v1.17. Affected versions
2.0.0
2.1.0
2.1.1
0.9.0
0.9.1
0.9.2
1.0.0
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
+ 14 more Show less
1.10.4
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
2.2.0
Fixed in
1.10.5
2.1.2
2.2.1
References
Updated Aug 07, 2026 · Source: OSV.dev |
1.10.1
patch
Dependencies (7)
Changelog
Compare changes
|
|
1.10.0
minor
2 CVEs
GHSA-hw46-3hmr-x9xv
Mar 12, 2025
omniauth-saml has dependency on ruby-saml version with Signature Wrapping Attack issue
Critical
SummaryThere are 2 new Critical Signature Wrapping Vulnerabilities (CVE-2025-25292, CVE-2025-25291) and a potential DDOS Moderated Vulneratiblity (CVE-2025-25293) affecting ruby-saml, a dependency of omniauth-saml. The fix will be applied to ruby-saml and released 12 March 2025, under version 1.18.0. Please upgrade the ruby-saml requirement to v1.18.0. ImpactSignature Wrapping Vulnerabilities allows an attacker to impersonate a user. Affected versions
2.2.0
2.2.1
2.2.2
2.0.0
2.1.0
2.1.1
2.1.2
0.9.0
0.9.1
0.9.2
1.0.0
1.1.0
+ 18 more Show less
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.10.6
2.1.3
2.2.3
References
Updated Feb 04, 2026 · Source: OSV.dev
GHSA-cvp8-5r8g-fhvq
Sep 11, 2024
omniauth-saml vulnerable to Improper Verification of Cryptographic Signature
Critical
Network
Low
None
None
ruby-saml, the dependent SAML gem of omniauth-saml has a signature wrapping vulnerability in <= v1.12.0 and v1.13.0 to v1.16.0 , see https://github.com/SAML-Toolkits/ruby-saml/security/advisories/GHSA-jw9c-mfg7-9rx2 As a result, omniauth-saml created a new release by upgrading ruby-saml to the patched versions v1.17. Affected versions
2.0.0
2.1.0
2.1.1
0.9.0
0.9.1
0.9.2
1.0.0
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
+ 14 more Show less
1.10.4
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
2.2.0
Fixed in
1.10.5
2.1.2
2.2.1
References
Updated Aug 07, 2026 · Source: OSV.dev |
1.10.0
minor
Dependencies (7)
Changelog
Compare changes
|
|
1.9.0
minor
3 CVEs
GHSA-hw46-3hmr-x9xv
Mar 12, 2025
omniauth-saml has dependency on ruby-saml version with Signature Wrapping Attack issue
Critical
SummaryThere are 2 new Critical Signature Wrapping Vulnerabilities (CVE-2025-25292, CVE-2025-25291) and a potential DDOS Moderated Vulneratiblity (CVE-2025-25293) affecting ruby-saml, a dependency of omniauth-saml. The fix will be applied to ruby-saml and released 12 March 2025, under version 1.18.0. Please upgrade the ruby-saml requirement to v1.18.0. ImpactSignature Wrapping Vulnerabilities allows an attacker to impersonate a user. Affected versions
2.2.0
2.2.1
2.2.2
2.0.0
2.1.0
2.1.1
2.1.2
0.9.0
0.9.1
0.9.2
1.0.0
1.1.0
+ 18 more Show less
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.10.6
2.1.3
2.2.3
References
Updated Feb 04, 2026 · Source: OSV.dev
GHSA-cvp8-5r8g-fhvq
Sep 11, 2024
omniauth-saml vulnerable to Improper Verification of Cryptographic Signature
Critical
Network
Low
None
None
ruby-saml, the dependent SAML gem of omniauth-saml has a signature wrapping vulnerability in <= v1.12.0 and v1.13.0 to v1.16.0 , see https://github.com/SAML-Toolkits/ruby-saml/security/advisories/GHSA-jw9c-mfg7-9rx2 As a result, omniauth-saml created a new release by upgrading ruby-saml to the patched versions v1.17. Affected versions
2.0.0
2.1.0
2.1.1
0.9.0
0.9.1
0.9.2
1.0.0
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
+ 14 more Show less
1.10.4
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
2.2.0
Fixed in
1.10.5
2.1.2
2.2.1
References
Updated Aug 07, 2026 · Source: OSV.dev
CVE-2017-11430
GHSA-94hm-8q65-rmxm
Jul 05, 2019
OmniAuth-SAML authentication bypass via incorrect XML canonicalization and DOM traversal
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
OmniAuth OmniAuth-SAML 1.9.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryptographic signature, allowing the attack to potentially bypass authentication to SAML service providers. Affected versions
0.9.0
0.9.1
0.9.2
1.0.0
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 5 more Show less
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.10.0
References
Updated Feb 16, 2024 · Source: OSV.dev |
1.9.0
minor
Dependencies (7)
Changelog
Compare changes
|
|
1.8.1
patch
3 CVEs
GHSA-hw46-3hmr-x9xv
Mar 12, 2025
omniauth-saml has dependency on ruby-saml version with Signature Wrapping Attack issue
Critical
SummaryThere are 2 new Critical Signature Wrapping Vulnerabilities (CVE-2025-25292, CVE-2025-25291) and a potential DDOS Moderated Vulneratiblity (CVE-2025-25293) affecting ruby-saml, a dependency of omniauth-saml. The fix will be applied to ruby-saml and released 12 March 2025, under version 1.18.0. Please upgrade the ruby-saml requirement to v1.18.0. ImpactSignature Wrapping Vulnerabilities allows an attacker to impersonate a user. Affected versions
2.2.0
2.2.1
2.2.2
2.0.0
2.1.0
2.1.1
2.1.2
0.9.0
0.9.1
0.9.2
1.0.0
1.1.0
+ 18 more Show less
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.10.6
2.1.3
2.2.3
References
Updated Feb 04, 2026 · Source: OSV.dev
GHSA-cvp8-5r8g-fhvq
Sep 11, 2024
omniauth-saml vulnerable to Improper Verification of Cryptographic Signature
Critical
Network
Low
None
None
ruby-saml, the dependent SAML gem of omniauth-saml has a signature wrapping vulnerability in <= v1.12.0 and v1.13.0 to v1.16.0 , see https://github.com/SAML-Toolkits/ruby-saml/security/advisories/GHSA-jw9c-mfg7-9rx2 As a result, omniauth-saml created a new release by upgrading ruby-saml to the patched versions v1.17. Affected versions
2.0.0
2.1.0
2.1.1
0.9.0
0.9.1
0.9.2
1.0.0
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
+ 14 more Show less
1.10.4
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
2.2.0
Fixed in
1.10.5
2.1.2
2.2.1
References
Updated Aug 07, 2026 · Source: OSV.dev
CVE-2017-11430
GHSA-94hm-8q65-rmxm
Jul 05, 2019
OmniAuth-SAML authentication bypass via incorrect XML canonicalization and DOM traversal
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
OmniAuth OmniAuth-SAML 1.9.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryptographic signature, allowing the attack to potentially bypass authentication to SAML service providers. Affected versions
0.9.0
0.9.1
0.9.2
1.0.0
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 5 more Show less
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.10.0
References
Updated Feb 16, 2024 · Source: OSV.dev |
1.8.1
patch
Dependencies (7)
Changelog
Compare changes
|
|
1.8.0
minor
3 CVEs
GHSA-hw46-3hmr-x9xv
Mar 12, 2025
omniauth-saml has dependency on ruby-saml version with Signature Wrapping Attack issue
Critical
SummaryThere are 2 new Critical Signature Wrapping Vulnerabilities (CVE-2025-25292, CVE-2025-25291) and a potential DDOS Moderated Vulneratiblity (CVE-2025-25293) affecting ruby-saml, a dependency of omniauth-saml. The fix will be applied to ruby-saml and released 12 March 2025, under version 1.18.0. Please upgrade the ruby-saml requirement to v1.18.0. ImpactSignature Wrapping Vulnerabilities allows an attacker to impersonate a user. Affected versions
2.2.0
2.2.1
2.2.2
2.0.0
2.1.0
2.1.1
2.1.2
0.9.0
0.9.1
0.9.2
1.0.0
1.1.0
+ 18 more Show less
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.10.6
2.1.3
2.2.3
References
Updated Feb 04, 2026 · Source: OSV.dev
GHSA-cvp8-5r8g-fhvq
Sep 11, 2024
omniauth-saml vulnerable to Improper Verification of Cryptographic Signature
Critical
Network
Low
None
None
ruby-saml, the dependent SAML gem of omniauth-saml has a signature wrapping vulnerability in <= v1.12.0 and v1.13.0 to v1.16.0 , see https://github.com/SAML-Toolkits/ruby-saml/security/advisories/GHSA-jw9c-mfg7-9rx2 As a result, omniauth-saml created a new release by upgrading ruby-saml to the patched versions v1.17. Affected versions
2.0.0
2.1.0
2.1.1
0.9.0
0.9.1
0.9.2
1.0.0
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
+ 14 more Show less
1.10.4
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
2.2.0
Fixed in
1.10.5
2.1.2
2.2.1
References
Updated Aug 07, 2026 · Source: OSV.dev
CVE-2017-11430
GHSA-94hm-8q65-rmxm
Jul 05, 2019
OmniAuth-SAML authentication bypass via incorrect XML canonicalization and DOM traversal
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
OmniAuth OmniAuth-SAML 1.9.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryptographic signature, allowing the attack to potentially bypass authentication to SAML service providers. Affected versions
0.9.0
0.9.1
0.9.2
1.0.0
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 5 more Show less
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.10.0
References
Updated Feb 16, 2024 · Source: OSV.dev |
1.8.0
minor
Dependencies (7)
Changelog
Compare changes
|
|
1.7.0
minor
3 CVEs
GHSA-hw46-3hmr-x9xv
Mar 12, 2025
omniauth-saml has dependency on ruby-saml version with Signature Wrapping Attack issue
Critical
SummaryThere are 2 new Critical Signature Wrapping Vulnerabilities (CVE-2025-25292, CVE-2025-25291) and a potential DDOS Moderated Vulneratiblity (CVE-2025-25293) affecting ruby-saml, a dependency of omniauth-saml. The fix will be applied to ruby-saml and released 12 March 2025, under version 1.18.0. Please upgrade the ruby-saml requirement to v1.18.0. ImpactSignature Wrapping Vulnerabilities allows an attacker to impersonate a user. Affected versions
2.2.0
2.2.1
2.2.2
2.0.0
2.1.0
2.1.1
2.1.2
0.9.0
0.9.1
0.9.2
1.0.0
1.1.0
+ 18 more Show less
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.10.6
2.1.3
2.2.3
References
Updated Feb 04, 2026 · Source: OSV.dev
GHSA-cvp8-5r8g-fhvq
Sep 11, 2024
omniauth-saml vulnerable to Improper Verification of Cryptographic Signature
Critical
Network
Low
None
None
ruby-saml, the dependent SAML gem of omniauth-saml has a signature wrapping vulnerability in <= v1.12.0 and v1.13.0 to v1.16.0 , see https://github.com/SAML-Toolkits/ruby-saml/security/advisories/GHSA-jw9c-mfg7-9rx2 As a result, omniauth-saml created a new release by upgrading ruby-saml to the patched versions v1.17. Affected versions
2.0.0
2.1.0
2.1.1
0.9.0
0.9.1
0.9.2
1.0.0
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
+ 14 more Show less
1.10.4
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
2.2.0
Fixed in
1.10.5
2.1.2
2.2.1
References
Updated Aug 07, 2026 · Source: OSV.dev
CVE-2017-11430
GHSA-94hm-8q65-rmxm
Jul 05, 2019
OmniAuth-SAML authentication bypass via incorrect XML canonicalization and DOM traversal
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
OmniAuth OmniAuth-SAML 1.9.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryptographic signature, allowing the attack to potentially bypass authentication to SAML service providers. Affected versions
0.9.0
0.9.1
0.9.2
1.0.0
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 5 more Show less
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.10.0
References
Updated Feb 16, 2024 · Source: OSV.dev |
1.7.0
minor
Dependencies (7)
Changelog
Compare changes
|
|
1.6.0
minor
3 CVEs
GHSA-hw46-3hmr-x9xv
Mar 12, 2025
omniauth-saml has dependency on ruby-saml version with Signature Wrapping Attack issue
Critical
SummaryThere are 2 new Critical Signature Wrapping Vulnerabilities (CVE-2025-25292, CVE-2025-25291) and a potential DDOS Moderated Vulneratiblity (CVE-2025-25293) affecting ruby-saml, a dependency of omniauth-saml. The fix will be applied to ruby-saml and released 12 March 2025, under version 1.18.0. Please upgrade the ruby-saml requirement to v1.18.0. ImpactSignature Wrapping Vulnerabilities allows an attacker to impersonate a user. Affected versions
2.2.0
2.2.1
2.2.2
2.0.0
2.1.0
2.1.1
2.1.2
0.9.0
0.9.1
0.9.2
1.0.0
1.1.0
+ 18 more Show less
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.10.6
2.1.3
2.2.3
References
Updated Feb 04, 2026 · Source: OSV.dev
GHSA-cvp8-5r8g-fhvq
Sep 11, 2024
omniauth-saml vulnerable to Improper Verification of Cryptographic Signature
Critical
Network
Low
None
None
ruby-saml, the dependent SAML gem of omniauth-saml has a signature wrapping vulnerability in <= v1.12.0 and v1.13.0 to v1.16.0 , see https://github.com/SAML-Toolkits/ruby-saml/security/advisories/GHSA-jw9c-mfg7-9rx2 As a result, omniauth-saml created a new release by upgrading ruby-saml to the patched versions v1.17. Affected versions
2.0.0
2.1.0
2.1.1
0.9.0
0.9.1
0.9.2
1.0.0
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
+ 14 more Show less
1.10.4
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
2.2.0
Fixed in
1.10.5
2.1.2
2.2.1
References
Updated Aug 07, 2026 · Source: OSV.dev
CVE-2017-11430
GHSA-94hm-8q65-rmxm
Jul 05, 2019
OmniAuth-SAML authentication bypass via incorrect XML canonicalization and DOM traversal
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
OmniAuth OmniAuth-SAML 1.9.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryptographic signature, allowing the attack to potentially bypass authentication to SAML service providers. Affected versions
0.9.0
0.9.1
0.9.2
1.0.0
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 5 more Show less
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.10.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.5.0
minor
3 CVEs
GHSA-hw46-3hmr-x9xv
Mar 12, 2025
omniauth-saml has dependency on ruby-saml version with Signature Wrapping Attack issue
Critical
SummaryThere are 2 new Critical Signature Wrapping Vulnerabilities (CVE-2025-25292, CVE-2025-25291) and a potential DDOS Moderated Vulneratiblity (CVE-2025-25293) affecting ruby-saml, a dependency of omniauth-saml. The fix will be applied to ruby-saml and released 12 March 2025, under version 1.18.0. Please upgrade the ruby-saml requirement to v1.18.0. ImpactSignature Wrapping Vulnerabilities allows an attacker to impersonate a user. Affected versions
2.2.0
2.2.1
2.2.2
2.0.0
2.1.0
2.1.1
2.1.2
0.9.0
0.9.1
0.9.2
1.0.0
1.1.0
+ 18 more Show less
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.10.6
2.1.3
2.2.3
References
Updated Feb 04, 2026 · Source: OSV.dev
GHSA-cvp8-5r8g-fhvq
Sep 11, 2024
omniauth-saml vulnerable to Improper Verification of Cryptographic Signature
Critical
Network
Low
None
None
ruby-saml, the dependent SAML gem of omniauth-saml has a signature wrapping vulnerability in <= v1.12.0 and v1.13.0 to v1.16.0 , see https://github.com/SAML-Toolkits/ruby-saml/security/advisories/GHSA-jw9c-mfg7-9rx2 As a result, omniauth-saml created a new release by upgrading ruby-saml to the patched versions v1.17. Affected versions
2.0.0
2.1.0
2.1.1
0.9.0
0.9.1
0.9.2
1.0.0
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
+ 14 more Show less
1.10.4
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
2.2.0
Fixed in
1.10.5
2.1.2
2.2.1
References
Updated Aug 07, 2026 · Source: OSV.dev
CVE-2017-11430
GHSA-94hm-8q65-rmxm
Jul 05, 2019
OmniAuth-SAML authentication bypass via incorrect XML canonicalization and DOM traversal
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
OmniAuth OmniAuth-SAML 1.9.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryptographic signature, allowing the attack to potentially bypass authentication to SAML service providers. Affected versions
0.9.0
0.9.1
0.9.2
1.0.0
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 5 more Show less
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.10.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.4.2
patch
3 CVEs
GHSA-hw46-3hmr-x9xv
Mar 12, 2025
omniauth-saml has dependency on ruby-saml version with Signature Wrapping Attack issue
Critical
SummaryThere are 2 new Critical Signature Wrapping Vulnerabilities (CVE-2025-25292, CVE-2025-25291) and a potential DDOS Moderated Vulneratiblity (CVE-2025-25293) affecting ruby-saml, a dependency of omniauth-saml. The fix will be applied to ruby-saml and released 12 March 2025, under version 1.18.0. Please upgrade the ruby-saml requirement to v1.18.0. ImpactSignature Wrapping Vulnerabilities allows an attacker to impersonate a user. Affected versions
2.2.0
2.2.1
2.2.2
2.0.0
2.1.0
2.1.1
2.1.2
0.9.0
0.9.1
0.9.2
1.0.0
1.1.0
+ 18 more Show less
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.10.6
2.1.3
2.2.3
References
Updated Feb 04, 2026 · Source: OSV.dev
GHSA-cvp8-5r8g-fhvq
Sep 11, 2024
omniauth-saml vulnerable to Improper Verification of Cryptographic Signature
Critical
Network
Low
None
None
ruby-saml, the dependent SAML gem of omniauth-saml has a signature wrapping vulnerability in <= v1.12.0 and v1.13.0 to v1.16.0 , see https://github.com/SAML-Toolkits/ruby-saml/security/advisories/GHSA-jw9c-mfg7-9rx2 As a result, omniauth-saml created a new release by upgrading ruby-saml to the patched versions v1.17. Affected versions
2.0.0
2.1.0
2.1.1
0.9.0
0.9.1
0.9.2
1.0.0
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
+ 14 more Show less
1.10.4
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
2.2.0
Fixed in
1.10.5
2.1.2
2.2.1
References
Updated Aug 07, 2026 · Source: OSV.dev
CVE-2017-11430
GHSA-94hm-8q65-rmxm
Jul 05, 2019
OmniAuth-SAML authentication bypass via incorrect XML canonicalization and DOM traversal
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
OmniAuth OmniAuth-SAML 1.9.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryptographic signature, allowing the attack to potentially bypass authentication to SAML service providers. Affected versions
0.9.0
0.9.1
0.9.2
1.0.0
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 5 more Show less
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.10.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.4.1
patch
3 CVEs
GHSA-hw46-3hmr-x9xv
Mar 12, 2025
omniauth-saml has dependency on ruby-saml version with Signature Wrapping Attack issue
Critical
SummaryThere are 2 new Critical Signature Wrapping Vulnerabilities (CVE-2025-25292, CVE-2025-25291) and a potential DDOS Moderated Vulneratiblity (CVE-2025-25293) affecting ruby-saml, a dependency of omniauth-saml. The fix will be applied to ruby-saml and released 12 March 2025, under version 1.18.0. Please upgrade the ruby-saml requirement to v1.18.0. ImpactSignature Wrapping Vulnerabilities allows an attacker to impersonate a user. Affected versions
2.2.0
2.2.1
2.2.2
2.0.0
2.1.0
2.1.1
2.1.2
0.9.0
0.9.1
0.9.2
1.0.0
1.1.0
+ 18 more Show less
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.10.6
2.1.3
2.2.3
References
Updated Feb 04, 2026 · Source: OSV.dev
GHSA-cvp8-5r8g-fhvq
Sep 11, 2024
omniauth-saml vulnerable to Improper Verification of Cryptographic Signature
Critical
Network
Low
None
None
ruby-saml, the dependent SAML gem of omniauth-saml has a signature wrapping vulnerability in <= v1.12.0 and v1.13.0 to v1.16.0 , see https://github.com/SAML-Toolkits/ruby-saml/security/advisories/GHSA-jw9c-mfg7-9rx2 As a result, omniauth-saml created a new release by upgrading ruby-saml to the patched versions v1.17. Affected versions
2.0.0
2.1.0
2.1.1
0.9.0
0.9.1
0.9.2
1.0.0
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
+ 14 more Show less
1.10.4
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
2.2.0
Fixed in
1.10.5
2.1.2
2.2.1
References
Updated Aug 07, 2026 · Source: OSV.dev
CVE-2017-11430
GHSA-94hm-8q65-rmxm
Jul 05, 2019
OmniAuth-SAML authentication bypass via incorrect XML canonicalization and DOM traversal
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
OmniAuth OmniAuth-SAML 1.9.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryptographic signature, allowing the attack to potentially bypass authentication to SAML service providers. Affected versions
0.9.0
0.9.1
0.9.2
1.0.0
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 5 more Show less
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.10.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.4.0
minor
3 CVEs
GHSA-hw46-3hmr-x9xv
Mar 12, 2025
omniauth-saml has dependency on ruby-saml version with Signature Wrapping Attack issue
Critical
SummaryThere are 2 new Critical Signature Wrapping Vulnerabilities (CVE-2025-25292, CVE-2025-25291) and a potential DDOS Moderated Vulneratiblity (CVE-2025-25293) affecting ruby-saml, a dependency of omniauth-saml. The fix will be applied to ruby-saml and released 12 March 2025, under version 1.18.0. Please upgrade the ruby-saml requirement to v1.18.0. ImpactSignature Wrapping Vulnerabilities allows an attacker to impersonate a user. Affected versions
2.2.0
2.2.1
2.2.2
2.0.0
2.1.0
2.1.1
2.1.2
0.9.0
0.9.1
0.9.2
1.0.0
1.1.0
+ 18 more Show less
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.10.6
2.1.3
2.2.3
References
Updated Feb 04, 2026 · Source: OSV.dev
GHSA-cvp8-5r8g-fhvq
Sep 11, 2024
omniauth-saml vulnerable to Improper Verification of Cryptographic Signature
Critical
Network
Low
None
None
ruby-saml, the dependent SAML gem of omniauth-saml has a signature wrapping vulnerability in <= v1.12.0 and v1.13.0 to v1.16.0 , see https://github.com/SAML-Toolkits/ruby-saml/security/advisories/GHSA-jw9c-mfg7-9rx2 As a result, omniauth-saml created a new release by upgrading ruby-saml to the patched versions v1.17. Affected versions
2.0.0
2.1.0
2.1.1
0.9.0
0.9.1
0.9.2
1.0.0
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
+ 14 more Show less
1.10.4
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
2.2.0
Fixed in
1.10.5
2.1.2
2.2.1
References
Updated Aug 07, 2026 · Source: OSV.dev
CVE-2017-11430
GHSA-94hm-8q65-rmxm
Jul 05, 2019
OmniAuth-SAML authentication bypass via incorrect XML canonicalization and DOM traversal
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
OmniAuth OmniAuth-SAML 1.9.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryptographic signature, allowing the attack to potentially bypass authentication to SAML service providers. Affected versions
0.9.0
0.9.1
0.9.2
1.0.0
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 5 more Show less
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.10.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.3.1
patch
3 CVEs
GHSA-hw46-3hmr-x9xv
Mar 12, 2025
omniauth-saml has dependency on ruby-saml version with Signature Wrapping Attack issue
Critical
SummaryThere are 2 new Critical Signature Wrapping Vulnerabilities (CVE-2025-25292, CVE-2025-25291) and a potential DDOS Moderated Vulneratiblity (CVE-2025-25293) affecting ruby-saml, a dependency of omniauth-saml. The fix will be applied to ruby-saml and released 12 March 2025, under version 1.18.0. Please upgrade the ruby-saml requirement to v1.18.0. ImpactSignature Wrapping Vulnerabilities allows an attacker to impersonate a user. Affected versions
2.2.0
2.2.1
2.2.2
2.0.0
2.1.0
2.1.1
2.1.2
0.9.0
0.9.1
0.9.2
1.0.0
1.1.0
+ 18 more Show less
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.10.6
2.1.3
2.2.3
References
Updated Feb 04, 2026 · Source: OSV.dev
GHSA-cvp8-5r8g-fhvq
Sep 11, 2024
omniauth-saml vulnerable to Improper Verification of Cryptographic Signature
Critical
Network
Low
None
None
ruby-saml, the dependent SAML gem of omniauth-saml has a signature wrapping vulnerability in <= v1.12.0 and v1.13.0 to v1.16.0 , see https://github.com/SAML-Toolkits/ruby-saml/security/advisories/GHSA-jw9c-mfg7-9rx2 As a result, omniauth-saml created a new release by upgrading ruby-saml to the patched versions v1.17. Affected versions
2.0.0
2.1.0
2.1.1
0.9.0
0.9.1
0.9.2
1.0.0
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
+ 14 more Show less
1.10.4
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
2.2.0
Fixed in
1.10.5
2.1.2
2.2.1
References
Updated Aug 07, 2026 · Source: OSV.dev
CVE-2017-11430
GHSA-94hm-8q65-rmxm
Jul 05, 2019
OmniAuth-SAML authentication bypass via incorrect XML canonicalization and DOM traversal
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
OmniAuth OmniAuth-SAML 1.9.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryptographic signature, allowing the attack to potentially bypass authentication to SAML service providers. Affected versions
0.9.0
0.9.1
0.9.2
1.0.0
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 5 more Show less
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.10.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.3.0
minor
3 CVEs
GHSA-hw46-3hmr-x9xv
Mar 12, 2025
omniauth-saml has dependency on ruby-saml version with Signature Wrapping Attack issue
Critical
SummaryThere are 2 new Critical Signature Wrapping Vulnerabilities (CVE-2025-25292, CVE-2025-25291) and a potential DDOS Moderated Vulneratiblity (CVE-2025-25293) affecting ruby-saml, a dependency of omniauth-saml. The fix will be applied to ruby-saml and released 12 March 2025, under version 1.18.0. Please upgrade the ruby-saml requirement to v1.18.0. ImpactSignature Wrapping Vulnerabilities allows an attacker to impersonate a user. Affected versions
2.2.0
2.2.1
2.2.2
2.0.0
2.1.0
2.1.1
2.1.2
0.9.0
0.9.1
0.9.2
1.0.0
1.1.0
+ 18 more Show less
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.10.6
2.1.3
2.2.3
References
Updated Feb 04, 2026 · Source: OSV.dev
GHSA-cvp8-5r8g-fhvq
Sep 11, 2024
omniauth-saml vulnerable to Improper Verification of Cryptographic Signature
Critical
Network
Low
None
None
ruby-saml, the dependent SAML gem of omniauth-saml has a signature wrapping vulnerability in <= v1.12.0 and v1.13.0 to v1.16.0 , see https://github.com/SAML-Toolkits/ruby-saml/security/advisories/GHSA-jw9c-mfg7-9rx2 As a result, omniauth-saml created a new release by upgrading ruby-saml to the patched versions v1.17. Affected versions
2.0.0
2.1.0
2.1.1
0.9.0
0.9.1
0.9.2
1.0.0
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
+ 14 more Show less
1.10.4
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
2.2.0
Fixed in
1.10.5
2.1.2
2.2.1
References
Updated Aug 07, 2026 · Source: OSV.dev
CVE-2017-11430
GHSA-94hm-8q65-rmxm
Jul 05, 2019
OmniAuth-SAML authentication bypass via incorrect XML canonicalization and DOM traversal
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
OmniAuth OmniAuth-SAML 1.9.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryptographic signature, allowing the attack to potentially bypass authentication to SAML service providers. Affected versions
0.9.0
0.9.1
0.9.2
1.0.0
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 5 more Show less
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.10.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.2.0
minor
3 CVEs
GHSA-hw46-3hmr-x9xv
Mar 12, 2025
omniauth-saml has dependency on ruby-saml version with Signature Wrapping Attack issue
Critical
SummaryThere are 2 new Critical Signature Wrapping Vulnerabilities (CVE-2025-25292, CVE-2025-25291) and a potential DDOS Moderated Vulneratiblity (CVE-2025-25293) affecting ruby-saml, a dependency of omniauth-saml. The fix will be applied to ruby-saml and released 12 March 2025, under version 1.18.0. Please upgrade the ruby-saml requirement to v1.18.0. ImpactSignature Wrapping Vulnerabilities allows an attacker to impersonate a user. Affected versions
2.2.0
2.2.1
2.2.2
2.0.0
2.1.0
2.1.1
2.1.2
0.9.0
0.9.1
0.9.2
1.0.0
1.1.0
+ 18 more Show less
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.10.6
2.1.3
2.2.3
References
Updated Feb 04, 2026 · Source: OSV.dev
GHSA-cvp8-5r8g-fhvq
Sep 11, 2024
omniauth-saml vulnerable to Improper Verification of Cryptographic Signature
Critical
Network
Low
None
None
ruby-saml, the dependent SAML gem of omniauth-saml has a signature wrapping vulnerability in <= v1.12.0 and v1.13.0 to v1.16.0 , see https://github.com/SAML-Toolkits/ruby-saml/security/advisories/GHSA-jw9c-mfg7-9rx2 As a result, omniauth-saml created a new release by upgrading ruby-saml to the patched versions v1.17. Affected versions
2.0.0
2.1.0
2.1.1
0.9.0
0.9.1
0.9.2
1.0.0
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
+ 14 more Show less
1.10.4
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
2.2.0
Fixed in
1.10.5
2.1.2
2.2.1
References
Updated Aug 07, 2026 · Source: OSV.dev
CVE-2017-11430
GHSA-94hm-8q65-rmxm
Jul 05, 2019
OmniAuth-SAML authentication bypass via incorrect XML canonicalization and DOM traversal
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
OmniAuth OmniAuth-SAML 1.9.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryptographic signature, allowing the attack to potentially bypass authentication to SAML service providers. Affected versions
0.9.0
0.9.1
0.9.2
1.0.0
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 5 more Show less
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.10.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.1.0
minor
3 CVEs
GHSA-hw46-3hmr-x9xv
Mar 12, 2025
omniauth-saml has dependency on ruby-saml version with Signature Wrapping Attack issue
Critical
SummaryThere are 2 new Critical Signature Wrapping Vulnerabilities (CVE-2025-25292, CVE-2025-25291) and a potential DDOS Moderated Vulneratiblity (CVE-2025-25293) affecting ruby-saml, a dependency of omniauth-saml. The fix will be applied to ruby-saml and released 12 March 2025, under version 1.18.0. Please upgrade the ruby-saml requirement to v1.18.0. ImpactSignature Wrapping Vulnerabilities allows an attacker to impersonate a user. Affected versions
2.2.0
2.2.1
2.2.2
2.0.0
2.1.0
2.1.1
2.1.2
0.9.0
0.9.1
0.9.2
1.0.0
1.1.0
+ 18 more Show less
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.10.6
2.1.3
2.2.3
References
Updated Feb 04, 2026 · Source: OSV.dev
GHSA-cvp8-5r8g-fhvq
Sep 11, 2024
omniauth-saml vulnerable to Improper Verification of Cryptographic Signature
Critical
Network
Low
None
None
ruby-saml, the dependent SAML gem of omniauth-saml has a signature wrapping vulnerability in <= v1.12.0 and v1.13.0 to v1.16.0 , see https://github.com/SAML-Toolkits/ruby-saml/security/advisories/GHSA-jw9c-mfg7-9rx2 As a result, omniauth-saml created a new release by upgrading ruby-saml to the patched versions v1.17. Affected versions
2.0.0
2.1.0
2.1.1
0.9.0
0.9.1
0.9.2
1.0.0
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
+ 14 more Show less
1.10.4
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
2.2.0
Fixed in
1.10.5
2.1.2
2.2.1
References
Updated Aug 07, 2026 · Source: OSV.dev
CVE-2017-11430
GHSA-94hm-8q65-rmxm
Jul 05, 2019
OmniAuth-SAML authentication bypass via incorrect XML canonicalization and DOM traversal
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
OmniAuth OmniAuth-SAML 1.9.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryptographic signature, allowing the attack to potentially bypass authentication to SAML service providers. Affected versions
0.9.0
0.9.1
0.9.2
1.0.0
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 5 more Show less
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.10.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.0.0
major
3 CVEs
GHSA-hw46-3hmr-x9xv
Mar 12, 2025
omniauth-saml has dependency on ruby-saml version with Signature Wrapping Attack issue
Critical
SummaryThere are 2 new Critical Signature Wrapping Vulnerabilities (CVE-2025-25292, CVE-2025-25291) and a potential DDOS Moderated Vulneratiblity (CVE-2025-25293) affecting ruby-saml, a dependency of omniauth-saml. The fix will be applied to ruby-saml and released 12 March 2025, under version 1.18.0. Please upgrade the ruby-saml requirement to v1.18.0. ImpactSignature Wrapping Vulnerabilities allows an attacker to impersonate a user. Affected versions
2.2.0
2.2.1
2.2.2
2.0.0
2.1.0
2.1.1
2.1.2
0.9.0
0.9.1
0.9.2
1.0.0
1.1.0
+ 18 more Show less
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.10.6
2.1.3
2.2.3
References
Updated Feb 04, 2026 · Source: OSV.dev
GHSA-cvp8-5r8g-fhvq
Sep 11, 2024
omniauth-saml vulnerable to Improper Verification of Cryptographic Signature
Critical
Network
Low
None
None
ruby-saml, the dependent SAML gem of omniauth-saml has a signature wrapping vulnerability in <= v1.12.0 and v1.13.0 to v1.16.0 , see https://github.com/SAML-Toolkits/ruby-saml/security/advisories/GHSA-jw9c-mfg7-9rx2 As a result, omniauth-saml created a new release by upgrading ruby-saml to the patched versions v1.17. Affected versions
2.0.0
2.1.0
2.1.1
0.9.0
0.9.1
0.9.2
1.0.0
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
+ 14 more Show less
1.10.4
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
2.2.0
Fixed in
1.10.5
2.1.2
2.2.1
References
Updated Aug 07, 2026 · Source: OSV.dev
CVE-2017-11430
GHSA-94hm-8q65-rmxm
Jul 05, 2019
OmniAuth-SAML authentication bypass via incorrect XML canonicalization and DOM traversal
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
OmniAuth OmniAuth-SAML 1.9.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryptographic signature, allowing the attack to potentially bypass authentication to SAML service providers. Affected versions
0.9.0
0.9.1
0.9.2
1.0.0
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 5 more Show less
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.10.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
0.9.2
patch
3 CVEs
GHSA-hw46-3hmr-x9xv
Mar 12, 2025
omniauth-saml has dependency on ruby-saml version with Signature Wrapping Attack issue
Critical
SummaryThere are 2 new Critical Signature Wrapping Vulnerabilities (CVE-2025-25292, CVE-2025-25291) and a potential DDOS Moderated Vulneratiblity (CVE-2025-25293) affecting ruby-saml, a dependency of omniauth-saml. The fix will be applied to ruby-saml and released 12 March 2025, under version 1.18.0. Please upgrade the ruby-saml requirement to v1.18.0. ImpactSignature Wrapping Vulnerabilities allows an attacker to impersonate a user. Affected versions
2.2.0
2.2.1
2.2.2
2.0.0
2.1.0
2.1.1
2.1.2
0.9.0
0.9.1
0.9.2
1.0.0
1.1.0
+ 18 more Show less
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.10.6
2.1.3
2.2.3
References
Updated Feb 04, 2026 · Source: OSV.dev
GHSA-cvp8-5r8g-fhvq
Sep 11, 2024
omniauth-saml vulnerable to Improper Verification of Cryptographic Signature
Critical
Network
Low
None
None
ruby-saml, the dependent SAML gem of omniauth-saml has a signature wrapping vulnerability in <= v1.12.0 and v1.13.0 to v1.16.0 , see https://github.com/SAML-Toolkits/ruby-saml/security/advisories/GHSA-jw9c-mfg7-9rx2 As a result, omniauth-saml created a new release by upgrading ruby-saml to the patched versions v1.17. Affected versions
2.0.0
2.1.0
2.1.1
0.9.0
0.9.1
0.9.2
1.0.0
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
+ 14 more Show less
1.10.4
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
2.2.0
Fixed in
1.10.5
2.1.2
2.2.1
References
Updated Aug 07, 2026 · Source: OSV.dev
CVE-2017-11430
GHSA-94hm-8q65-rmxm
Jul 05, 2019
OmniAuth-SAML authentication bypass via incorrect XML canonicalization and DOM traversal
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
OmniAuth OmniAuth-SAML 1.9.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryptographic signature, allowing the attack to potentially bypass authentication to SAML service providers. Affected versions
0.9.0
0.9.1
0.9.2
1.0.0
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 5 more Show less
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.10.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
0.9.1
patch
3 CVEs
GHSA-hw46-3hmr-x9xv
Mar 12, 2025
omniauth-saml has dependency on ruby-saml version with Signature Wrapping Attack issue
Critical
SummaryThere are 2 new Critical Signature Wrapping Vulnerabilities (CVE-2025-25292, CVE-2025-25291) and a potential DDOS Moderated Vulneratiblity (CVE-2025-25293) affecting ruby-saml, a dependency of omniauth-saml. The fix will be applied to ruby-saml and released 12 March 2025, under version 1.18.0. Please upgrade the ruby-saml requirement to v1.18.0. ImpactSignature Wrapping Vulnerabilities allows an attacker to impersonate a user. Affected versions
2.2.0
2.2.1
2.2.2
2.0.0
2.1.0
2.1.1
2.1.2
0.9.0
0.9.1
0.9.2
1.0.0
1.1.0
+ 18 more Show less
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.10.6
2.1.3
2.2.3
References
Updated Feb 04, 2026 · Source: OSV.dev
GHSA-cvp8-5r8g-fhvq
Sep 11, 2024
omniauth-saml vulnerable to Improper Verification of Cryptographic Signature
Critical
Network
Low
None
None
ruby-saml, the dependent SAML gem of omniauth-saml has a signature wrapping vulnerability in <= v1.12.0 and v1.13.0 to v1.16.0 , see https://github.com/SAML-Toolkits/ruby-saml/security/advisories/GHSA-jw9c-mfg7-9rx2 As a result, omniauth-saml created a new release by upgrading ruby-saml to the patched versions v1.17. Affected versions
2.0.0
2.1.0
2.1.1
0.9.0
0.9.1
0.9.2
1.0.0
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
+ 14 more Show less
1.10.4
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
2.2.0
Fixed in
1.10.5
2.1.2
2.2.1
References
Updated Aug 07, 2026 · Source: OSV.dev
CVE-2017-11430
GHSA-94hm-8q65-rmxm
Jul 05, 2019
OmniAuth-SAML authentication bypass via incorrect XML canonicalization and DOM traversal
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
OmniAuth OmniAuth-SAML 1.9.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryptographic signature, allowing the attack to potentially bypass authentication to SAML service providers. Affected versions
0.9.0
0.9.1
0.9.2
1.0.0
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 5 more Show less
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.10.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
0.9.0
initial
3 CVEs
GHSA-hw46-3hmr-x9xv
Mar 12, 2025
omniauth-saml has dependency on ruby-saml version with Signature Wrapping Attack issue
Critical
SummaryThere are 2 new Critical Signature Wrapping Vulnerabilities (CVE-2025-25292, CVE-2025-25291) and a potential DDOS Moderated Vulneratiblity (CVE-2025-25293) affecting ruby-saml, a dependency of omniauth-saml. The fix will be applied to ruby-saml and released 12 March 2025, under version 1.18.0. Please upgrade the ruby-saml requirement to v1.18.0. ImpactSignature Wrapping Vulnerabilities allows an attacker to impersonate a user. Affected versions
2.2.0
2.2.1
2.2.2
2.0.0
2.1.0
2.1.1
2.1.2
0.9.0
0.9.1
0.9.2
1.0.0
1.1.0
+ 18 more Show less
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.10.6
2.1.3
2.2.3
References
Updated Feb 04, 2026 · Source: OSV.dev
GHSA-cvp8-5r8g-fhvq
Sep 11, 2024
omniauth-saml vulnerable to Improper Verification of Cryptographic Signature
Critical
Network
Low
None
None
ruby-saml, the dependent SAML gem of omniauth-saml has a signature wrapping vulnerability in <= v1.12.0 and v1.13.0 to v1.16.0 , see https://github.com/SAML-Toolkits/ruby-saml/security/advisories/GHSA-jw9c-mfg7-9rx2 As a result, omniauth-saml created a new release by upgrading ruby-saml to the patched versions v1.17. Affected versions
2.0.0
2.1.0
2.1.1
0.9.0
0.9.1
0.9.2
1.0.0
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
+ 14 more Show less
1.10.4
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
2.2.0
Fixed in
1.10.5
2.1.2
2.2.1
References
Updated Aug 07, 2026 · Source: OSV.dev
CVE-2017-11430
GHSA-94hm-8q65-rmxm
Jul 05, 2019
OmniAuth-SAML authentication bypass via incorrect XML canonicalization and DOM traversal
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
OmniAuth OmniAuth-SAML 1.9.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryptographic signature, allowing the attack to potentially bypass authentication to SAML service providers. Affected versions
0.9.0
0.9.1
0.9.2
1.0.0
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 5 more Show less
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.10.0
References
Updated Feb 16, 2024 · Source: OSV.dev |