cognitive cybersecurity intelligence

News and Analysis

Search

Critical ruby-saml Vulnerabilities Let Attackers Bypass Authentication

Two critical vulnerabilities (CVE-2025-25291 and CVE-2025-25292) in the ruby-saml library could allow attackers to impersonate users and execute account takeover attacks. These flaws arise from differences in parsing XML with REXML and Nokogiri. Organizations must update to ruby-saml version 1.18.0 to mitigate these risks effectively.

Source: cybersecuritynews.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts