CyberzSOC

Applicability
← Back to CVE-2025-25291

CVE-2025-25291

SAML-Toolkits

Every applicability statement published about this vulnerability, kept as each source wrote it rather than merged into one verdict. Where sources disagree, both positions are shown.

Does it affect your version?

A statement that names no version covers the whole product, which is not the same as your version falling inside a range. Orderings marked best effort come from schemes with no published comparison algorithm; exact ones follow a published specification.

What each source says

OSV.dev (incl. GHSA)
precedence 80 · revised 2026-09-08
10 affected 10 fixed
CVE List v5 (CNA container)
precedence 60 · revised 2025-11-03
2 affected

Precedence decides which claim wins when two sources describe the same product over the same version range. It is a property of the source, not of the claim, and changing it re-ranks the data without re-reading a single document.

Statements (22)

Product Status Versions Remediation Source
gitlab affected < 17.9.2 vendor fix → 17.9.2 osv BIT-gitlab-2025-25291
https://github.com/omniauth/omniauth-saml affected < 1075827eb7d7b0926920c9b452f756d18de6deab vendor fix → 1075827eb7d7b0926920c9b452f756d18de6deab osv
https://github.com/omniauth/omniauth-saml affected >= ed52758c272f5afe81e3304d1f4e436e30021a2a, < 2eb30faada7936b2e2188e47a5b768f5643e6eae vendor fix → 2eb30faada7936b2e2188e47a5b768f5643e6eae osv
https://github.com/omniauth/omniauth-saml affected >= 4274e9d57e65f2dcaae4aa3b2accf831494f2ddd, < 34eb3541248e4ee56fa2189bd7b47f4748fe2f78 vendor fix → 34eb3541248e4ee56fa2189bd7b47f4748fe2f78 osv
https://github.com/omniauth/omniauth-saml affected < 48cc5b92e1dde8637a013dfd48cdf8ceadd499b2 vendor fix → 48cc5b92e1dde8637a013dfd48cdf8ceadd499b2 osv
https://github.com/omniauth/omniauth-saml affected >= 5da850c36bbf678674f9321032df428139d7e434, < 6a7c040049babe748ee1bb4ca13898c47189114c vendor fix → 6a7c040049babe748ee1bb4ca13898c47189114c osv
https://github.com/omniauth/omniauth-saml affected < e76c5b36bac40aedbf1ba7ffaaf495be63328cd9 vendor fix → e76c5b36bac40aedbf1ba7ffaaf495be63328cd9 osv
https://github.com/omniauth/omniauth-saml affected < e9c1cdbd0f9afa467b585de279db0cbd0fb8ae97 vendor fix → e9c1cdbd0f9afa467b585de279db0cbd0fb8ae97 osv
ruby-saml affected < 1.12.4 vendor fix → 1.12.4 osv GHSA-4vc4-m8qh-g8jm
ruby-saml affected >= 1.13.0, < 1.18.0 vendor fix → 1.18.0 osv GHSA-4vc4-m8qh-g8jm
gitlab fixed 17.9.2 vendor fix → 17.9.2 osv BIT-gitlab-2025-25291
https://github.com/omniauth/omniauth-saml fixed 1075827eb7d7b0926920c9b452f756d18de6deab vendor fix → 1075827eb7d7b0926920c9b452f756d18de6deab osv
https://github.com/omniauth/omniauth-saml fixed 2eb30faada7936b2e2188e47a5b768f5643e6eae vendor fix → 2eb30faada7936b2e2188e47a5b768f5643e6eae osv
https://github.com/omniauth/omniauth-saml fixed 34eb3541248e4ee56fa2189bd7b47f4748fe2f78 vendor fix → 34eb3541248e4ee56fa2189bd7b47f4748fe2f78 osv
https://github.com/omniauth/omniauth-saml fixed 48cc5b92e1dde8637a013dfd48cdf8ceadd499b2 vendor fix → 48cc5b92e1dde8637a013dfd48cdf8ceadd499b2 osv
https://github.com/omniauth/omniauth-saml fixed 6a7c040049babe748ee1bb4ca13898c47189114c vendor fix → 6a7c040049babe748ee1bb4ca13898c47189114c osv
https://github.com/omniauth/omniauth-saml fixed e76c5b36bac40aedbf1ba7ffaaf495be63328cd9 vendor fix → e76c5b36bac40aedbf1ba7ffaaf495be63328cd9 osv
https://github.com/omniauth/omniauth-saml fixed e9c1cdbd0f9afa467b585de279db0cbd0fb8ae97 vendor fix → e9c1cdbd0f9afa467b585de279db0cbd0fb8ae97 osv
ruby-saml fixed 1.12.4 vendor fix → 1.12.4 osv GHSA-4vc4-m8qh-g8jm
ruby-saml fixed 1.18.0 vendor fix → 1.18.0 osv GHSA-4vc4-m8qh-g8jm
SAML-Toolkits/ruby-saml SAML-Toolkits · ruby-saml affected < 1.12.4 none available cve_cna
SAML-Toolkits/ruby-saml SAML-Toolkits · ruby-saml affected >= 1.13.0, < 1.18.0 none available cve_cna

A claim with no version range is shown as written rather than expanded: a government catalog naming only a vendor and product is a real statement at zero granularity, and inventing bounds for it would put precision in the record that the source never offered.