GHSA-92rq-c8cf-prrq · Severity: high · Ecosystem: rubygems — Ruby SAML allows remote Denial of Service (DoS) with compressed SAML responses
ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. Prior to versions 1.12.4 and 1.18.0, ruby-saml is susceptible to remote Denial of Service (DoS) with compressed SAML responses. ruby-saml uses zlib to decompress SAML responses in case they're compressed. It is possible to bypass the message size check with a compressed assertion since the message size is checked before inflation and not after. This issue may lead to remote Denial of Service (DoS). Versions 1.12.4 and 1.18.0 fix the issue.
Conclusion & alert: CVE-2025-25293 is rated High Exploit Risk (64.7/100): CVSS High severity, with medium exploitation likelihood (EPSS 1.36%). Core evidence: 2 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ | |
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 6.22% | 1.36% | -4.87% |
| 2 | 2026-05-07 | 5.26% | 6.22% | +0.97% |
| 3 | 2026-04-21 | — | 5.26% | — |
Full EPSS history (26 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.7 | 4.0 | HIGH |
|
— | — | [email protected] |
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | [email protected] |
GHSA-92rq-c8cf-prrq · Severity: high · Ecosystem: rubygems — Ruby SAML allows remote Denial of Service (DoS) with compressed SAML responses
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
end-of-life | CVE-2025-25293 end-of-life priority: Debian including 1 source packages (ruby-saml), 2 status rows across 2 suites (bookworm, bullseye): open 1, resolved 1. | https://security-tracker.debian.org/tracker/CVE-2025-25293 |
ubuntu
|
medium | CVE-2025-25293 medium priority: Ubuntu including 1 source packages (ruby-saml), 9 status rows across 9 suites (bionic, focal, jammy, noble, oracular, plucky, questing, upstream, xenial): released 7, DNE 1, ignored 1. | https://ubuntu.com/security/CVE-2025-25293 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| omniauth | omniauth_saml | < 1.10.6 | cpe:2.3:a:omniauth:omniauth_saml:*:*:*:*:*:ruby:*:* |
| omniauth | omniauth_saml | >= 2.0.0, < 2.1.3 | cpe:2.3:a:omniauth:omniauth_saml:*:*:*:*:*:ruby:*:* |
| omniauth | omniauth_saml | >= 2.2.0, < 2.2.3 | cpe:2.3:a:omniauth:omniauth_saml:*:*:*:*:*:ruby:*:* |
| onelogin | ruby-saml | < 1.12.4 | cpe:2.3:a:onelogin:ruby-saml:*:*:*:*:*:*:*:* |
| onelogin | ruby-saml | >= 1.13.0, < 1.18.0 | cpe:2.3:a:onelogin:ruby-saml:*:*:*:*:*:*:*:* |