The ruby-saml library implements the client side of an SAML authorization. Versions up to and including 1.12.4, are vulnerable to authentication bypass through the libxml2 canonicalization process used by Nokogiri for document transformation, which allows an attacker to execute a Signature Wrapping attack. When libxml2’s canonicalization is invoked on an invalid XML input, it may return an empty string rather than a canonicalized node. ruby-saml then proceeds to compute the DigestValue over this empty string, treating it as if canonicalization succeeded. This issue is fixed in version 1.18.0.
The vulnerability results from improper error handling in the XML canonicalization process performed by the libxml2 library (via Nokogiri). When libxml2 processes malformed XML input, it may return an empty string instead of a properly canonicalized node instead of raising an error. The ruby-saml library then continues to calculate the DigestValue for this empty string, treating the operation as successful. Such an error enables an attacker to construct a specially crafted SAML response (Signature Wrapping attack), in which the digital signature is verified for different content than what is actually processed by the application.
An attacker can completely bypass the SAML-based authentication mechanism and impersonate any user, including an administrator, gaining unauthorized access to applications protected by ruby-saml.
Update the ruby-saml library to version 1.18.0, in which the issue has been fixed. The patch is available in the SAML-Toolkits/ruby-saml GitHub repository.
The ruby-saml library (OneLogin) in versions up to and including 1.12.4.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XOnelogin Ruby Saml
APPOnelogin< 1.18.0
Related vulnerabilities
Auth Bypass w ruby-saml przez atak Signature Wrapping (CVE-2025-66567)
Authentication bypass w ruby-saml poprzez Signature Wrapping (SAML SSO)
Pominięcie uwierzytelnienia SAML SSO przez atak Signature Wrapping w ruby-saml
Ruby-SAML: pominięcie weryfikacji podpisu odpowiedzi SAML — Auth Bypass
XPath injection i RCE w bibliotece ruby-saml (przed wersją 1.0.0)