DEBIAN-CVE-2025-54572

Source
https://security-tracker.debian.org/tracker/CVE-2025-54572
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-54572.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2025-54572
Upstream
Downstream
Published
2025-07-30T14:15:29Z
Modified
2026-09-01T20:04:23Z
Severity
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator
Summary
[none]
Details

The Ruby SAML library is for implementing the client side of a SAML authorization. In versions 1.18.0 and below, a denial-of-service vulnerability exists in ruby-saml even with the message_max_bytesize setting configured. The vulnerability occurs because the SAML response is validated for Base64 format prior to checking the message size, leading to potential resource exhaustion. This is fixed in version 1.18.1.

References

Affected packages

Debian:12 / ruby-saml

Package

Name
ruby-saml
Purl
pkg:deb/debian/ruby-saml?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.13.0-1
1.13.0-1+deb12u1
1.15.0-1
1.17.0-1

Ecosystem specific

{
    "urgency": "end-of-life"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-54572.json"