Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-54572

Опубликовано: 30 июл. 2025
Источник: nvd
EPSS Низкий

Описание

The Ruby SAML library is for implementing the client side of a SAML authorization. In versions 1.18.0 and below, a denial-of-service vulnerability exists in ruby-saml even with the message_max_bytesize setting configured. The vulnerability occurs because the SAML response is validated for Base64 format prior to checking the message size, leading to potential resource exhaustion. This is fixed in version 1.18.1.

EPSS

Процентиль: 17%
0.00056
Низкий

Дефекты

CWE-400

Связанные уязвимости

ubuntu
29 дней назад

The Ruby SAML library is for implementing the client side of a SAML authorization. In versions 1.18.0 and below, a denial-of-service vulnerability exists in ruby-saml even with the message_max_bytesize setting configured. The vulnerability occurs because the SAML response is validated for Base64 format prior to checking the message size, leading to potential resource exhaustion. This is fixed in version 1.18.1.

debian
29 дней назад

The Ruby SAML library is for implementing the client side of a SAML au ...

github
29 дней назад

Ruby SAML DOS vulnerability with large SAML response

EPSS

Процентиль: 17%
0.00056
Низкий

Дефекты

CWE-400