Junglewise Threat Intelligence

CVE-2025-66567: Ruby-saml has a SAML authentication bypass due to namespace handling (parser differential)

CVE-2025-66567 · Severity: medium · CVSS 4 · Published 2025-12-08

Vendors: RubyGems.

Executive brief

Ruby-saml has a SAML authentication bypass due to namespace handling (parser differential)

Affected products

  • RubyGems ruby-saml

Related threats