# ruby-saml denial of service via compressed SAML messages

Source: https://startwithidentity.com/cves/cve-2025-25293/
Last updated: 2026-08-29
License: content by Start with Identity. Cite the source URL.

---

## What broke

ruby-saml accepted compressed [SAML](https://startwithidentity.com/glossary/saml/) messages without a tight bound on the decompressed size. A crafted payload can expand into a denial-of-service against the process that verifies SSO responses. Patched in the same March 2025 release as [CVE-2025-25291](https://startwithidentity.com/cves/cve-2025-25291/) and [CVE-2025-25292](https://startwithidentity.com/cves/cve-2025-25292/).

## Why it matters

This one does not log anyone in as admin. It takes the SSO endpoint offline, which for a workforce [IdP](https://startwithidentity.com/glossary/identity-provider/) is still an identity incident: password resets, break-glass, and help-desk social engineering spike the moment login is down. Attackers who cannot wrap a signature will happily knock the verifier over instead.

## What to do

- Upgrade ruby-saml with the wrapping fixes. Do not cherry-pick only the critical CVEs.
- Cap compressed SAML (and HTTP-Redirect binding) payloads at the reverse proxy, not only in the library.
- Watch for a sudden rise in 5xx on ACS endpoints after a failed login burst.

## After you patch

A SAML bypass means the service provider accepted an assertion it should have rejected, so anyone who exploited it authenticated as a real user and left a normal-looking log line.

- **Revoke every session** issued by the affected service provider, then rotate its session signing keys. Patching stops new forgeries and does nothing about sessions already minted.
- **Audit administrative accounts and group memberships** for changes during the exposure window. Signing in as an administrator is the point of this class, and adding a second account is the standard persistence step.
- **Rotate the identity provider signing certificate** if the flaw involved signature validation, and confirm the service provider pins the expected certificate rather than trusting anything in the assertion.
- **Check your own implementation for the same class**: exact-match comparison on verification results, rejection of unexpected signature algorithms, and audience and recency checks on every assertion. See [SAML 2.0](https://startwithidentity.com/standards/saml-2-0/) and [SAML vs OIDC](https://startwithidentity.com/guides/fundamentals/saml-vs-oidc/).

## Sources

- [NVD: CVE-2025-25293](https://nvd.nist.gov/vuln/detail/CVE-2025-25293)
