10 Total advisories
10 Vulnerabilities
0 Malware
Dependency scanning
Check whether ruby-saml is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
UNKNOWN
CVE-2025-54572
Ruby SAML DOS vulnerability with large SAML response
CRITICAL 10.0
CVE-2024-45409
SAML authentication bypass via Incorrect XPath selector
HIGH 7.5
CVE-2025-25293
Ruby SAML allows remote Denial of Service (DoS) with compressed SAML responses
CRITICAL 9.8
CVE-2025-25292
Ruby SAML allows a SAML authentication bypass due to namespace handling (parser differential)
UNKNOWN
CVE-2025-66567
Ruby-saml has a SAML authentication bypass due to namespace handling (parser differential)
CRITICAL 9.8
CVE-2025-25291
Ruby SAML allows a SAML authentication bypass due to DOCTYPE handling (parser differential)
UNKNOWN
CVE-2025-66568
Ruby-saml allows a Libxml2 Canonicalization error to bypass Digest/Signature validation
CRITICAL 9.8
CVE-2015-20108
ruby-saml vulnerable to XPath injection
HIGH 7.5
CVE-2016-5697
Ruby-saml allows attackers to perform XML signature wrapping attacks
HIGH 7.7
CVE-2017-11428
Ruby-SAML Improper Authentication vulnerability
Browse more RubyGems advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes