CVE-2025-25292: Netapp Storagegrid
Critical severity, CVSS 9.8. EPSS: 65.1% chance of exploitation in the next 30 days.
ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. An authentication bypass vulnerability was found in ruby-saml prior to versions 1.12.4 and 1.18.0 due to a parser differential. ReXML and Nokogiri parse XML differently, the parsers can generate entirely different document structures from the same XML input. That allows an attacker to be able to execute a Signature Wrapping attack. This issue may lead to authentication bypass. Versions 1.12.4 and 1.18.0 contain a patch for the issue.
Affected products
- Netapp Storagegrid: affected versions not specified
- Omniauth Omniauth SAML: before 1.10.6 (fixed in 1.10.6); from 2.0.0, before 2.1.3 (fixed in 2.1.3); from 2.2.0, before 2.2.3 (fixed in 2.2.3)
- Onelogin Ruby-SAML: before 1.12.4 (fixed in 1.12.4); from 1.13.0, before 1.18.0 (fixed in 1.18.0)
Published 2025-03-12. Last modified 2026-06-17.