GHSA-rrqh-93c8-j966 · Severity: medium · Ecosystem: rubygems — Ruby SAML DOS vulnerability with large SAML response
The Ruby SAML library is for implementing the client side of a SAML authorization. In versions 1.18.0 and below, a denial-of-service vulnerability exists in ruby-saml even with the message_max_bytesize setting configured. The vulnerability occurs because the SAML response is validated for Base64 format prior to checking the message size, leading to potential resource exhaustion. This is fixed in version 1.18.1.
Conclusion & alert: CVE-2025-54572 is rated Moderate Risk (52.2/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 0.58%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-05-26 | 0.16% | 0.58% | +0.42% |
| 2 | 2026-05-16 | 0.06% | 0.16% | +0.10% |
| 3 | 2025-08-05 | — | 0.06% | — |
Full EPSS history (4 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 6.9 | 4.0 | MEDIUM |
|
— | — | [email protected] |
GHSA-rrqh-93c8-j966 · Severity: medium · Ecosystem: rubygems — Ruby SAML DOS vulnerability with large SAML response
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2025-54572 not yet assigned priority: Debian including 1 source packages (ruby-saml), 2 status rows across 2 suites (bookworm, bullseye): open 1, resolved 1. | https://security-tracker.debian.org/tracker/CVE-2025-54572 |
ubuntu
|
medium | CVE-2025-54572 medium priority: Ubuntu including 1 source packages (ruby-saml), 8 status rows across 8 suites (bionic, focal, jammy, noble, plucky, questing, upstream, xenial): needs-triage 6, DNE 1, ignored 1. | https://ubuntu.com/security/CVE-2025-54572 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| No affected products in dataset. | |||