Skip to content

Commit bbe7c00

Browse files
authored
Add warning about CVE-2025-66567 and CVE-2025-66568
CVE-2025-66567 and CVE-2025-66568 affects ruby-saml <= 1.12.4. Use ruby-saml 1.18.1 instead.
1 parent 75546f4 commit bbe7c00

File tree

1 file changed

+2
-0
lines changed

1 file changed

+2
-0
lines changed

README.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -10,6 +10,8 @@ Minor and patch versions of Ruby SAML may introduce breaking changes. Please rea
1010

1111
## Vulnerability Notice
1212

13+
[CVE-2025-66568](https://github.com/SAML-Toolkits/ruby-saml/security/advisories/GHSA-9v8j-x534-2fx3) and [CVE-2025-66567](https://github.com/SAML-Toolkits/ruby-saml/security/advisories/GHSA-9v8j-x534-2fx3) affects version ruby-saml <= 1.12.4, upgrade to 1.18.1
14+
1315
CVE-2025-54572 affects version ruby-saml < 1.18.1
1416

1517
There are critical vulnerabilities affecting ruby-saml < 1.18.0, two of them allows SAML authentication bypass (CVE-2025-25291, CVE-2025-25292, CVE-2025-25293). Please upgrade to a fixed version (1.18.0)

0 commit comments

Comments
 (0)