<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 04:53:48 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-257570</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-257570</link>
      <description>EUVD-2026-257570</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-257570</guid>
    </item>
    <item>
      <title>fkie_cve-2025-54572</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-54572</link>
      <description>&lt;p&gt;The Ruby SAML library is for implementing the client side of a SAML authorization. In versions 1.18.0 and below, a denial-of-service vulnerability exists in ruby-saml even with the message_max_bytesize setting configured. The vulnerability occurs because the SAML response is validated for Base64 format prior to checking the message size, leading to potential resource exhaustion. This is fixed in version 1.18.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The Ruby SAML library is for implementing the client side of a SAML authorization. In versions 1.18.0 and below, a denial-of-service vulnerability exists in ruby-saml even with the message_max_bytesize setting configured. The vulnerability occurs because the SAML response is validated for Base64 format prior to checking the message size, leading to potential resource exhaustion. This is fixed in version 1.18.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-54572</guid>
    </item>
    <item>
      <title>GHSA-rrqh-93c8-j966 — Ruby SAML DOS vulnerability with large SAML response</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-rrqh-93c8-j966</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: ruby-saml&lt;/p&gt;
&lt;p&gt;### Summary
A denial-of-service vulnerability exists in ruby-saml even with the message_max_bytesize setting configured. The vulnerability occurs because the SAML response is validated for Base64 format prior to checking the message size, leading to potential resource exhaustion.&lt;/p&gt;
&lt;p&gt;### Details
`ruby-saml` includes a `message_max_bytesize` setting intended to prevent DOS attacks and decompression bombs. However, this protection is ineffective in some cases due to the order of operations in the code:&lt;/p&gt;
&lt;p&gt;https://github.com/SAML-Toolkits/ruby-saml/blob/fbbedc978300deb9355a8e505849666974ef2e67/lib/onelogin/ruby-saml/saml_message.rb&lt;/p&gt;
&lt;p&gt;```ruby
      def decode_raw_saml(saml, settings = nil)
        return saml unless base64_encoded?(saml) # &amp;lt;--- Issue here. Should be moved after next code block.&lt;/p&gt;
&lt;p&gt;settings = OneLogin::RubySaml::Settings.new if settings.nil?
        if saml.bytesize &amp;gt; settings.message_max_bytesize
          raise ValidationError.new(&amp;#34;Encoded SAML Message exceeds &amp;#34; + settings.message_max_bytesize.to_s + &amp;#34; bytes, so was rejected&amp;#34;)
        end&lt;/p&gt;
&lt;p&gt;decoded = decode(saml)
        ...
      end
```&lt;/p&gt;
&lt;p&gt;The vulnerability is in the execution order. Prior to checking bytesize the `base64_encoded?` function performs regex matching on the entire input string:&lt;/p&gt;
&lt;p&gt;```ruby
!!string.gsub(/[\r\n]|\\r|\\n|\s/, &amp;#34;&amp;#34;).match(BASE64_FORMAT)
```&lt;/p&gt;
&lt;p&gt;### Impact
_What kind of vulnerability is it? Who is impacted?_&lt;/p&gt;
&lt;p&gt;When successfully exploited, this vulnerability can lead to:&lt;/p&gt;
&lt;p&gt;- Excessive mem…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: ruby-saml&lt;/p&gt;
&lt;p&gt;### Summary
A denial-of-service vulnerability exists in ruby-saml even with the message_max_bytesize setting configured. The vulnerability occurs because the SAML response is validated for Base64 format prior to checking the message size, leading to potential resource exhaustion.&lt;/p&gt;
&lt;p&gt;### Details
`ruby-saml` includes a `message_max_bytesize` setting intended to prevent DOS attacks and decompression bombs. However, this protection is ineffective in some cases due to the order of operations in the code:&lt;/p&gt;
&lt;p&gt;https://github.com/SAML-Toolkits/ruby-saml/blob/fbbedc978300deb9355a8e505849666974ef2e67/lib/onelogin/ruby-saml/saml_message.rb&lt;/p&gt;
&lt;p&gt;```ruby
      def decode_raw_saml(saml, settings = nil)
        return saml unless base64_encoded?(saml) # &amp;lt;--- Issue here. Should be moved after next code block.&lt;/p&gt;
&lt;p&gt;settings = OneLogin::RubySaml::Settings.new if settings.nil?
        if saml.bytesize &amp;gt; settings.message_max_bytesize
          raise ValidationError.new(&amp;#34;Encoded SAML Message exceeds &amp;#34; + settings.message_max_bytesize.to_s + &amp;#34; bytes, so was rejected&amp;#34;)
        end&lt;/p&gt;
&lt;p&gt;decoded = decode(saml)
        ...
      end
```&lt;/p&gt;
&lt;p&gt;The vulnerability is in the execution order. Prior to checking bytesize the `base64_encoded?` function performs regex matching on the entire input string:&lt;/p&gt;
&lt;p&gt;```ruby
!!string.gsub(/[\r\n]|\\r|\\n|\s/, &amp;#34;&amp;#34;).match(BASE64_FORMAT)
```&lt;/p&gt;
&lt;p&gt;### Impact
_What kind of vulnerability is it? Who is impacted?_&lt;/p&gt;
&lt;p&gt;When successfully exploited, this vulnerability can lead to:&lt;/p&gt;
&lt;p&gt;- Excessive mem…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-rrqh-93c8-j966</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-54572</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-54572</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: ruby-saml, Ubuntu:Pro:18.04:LTS: ruby-saml, Ubuntu:Pro:20.04:LTS: ruby-saml, Ubuntu:Pro:22.04:LTS: ruby-saml, Ubuntu:Pro:24.04:LTS: ruby-saml&lt;/p&gt;
&lt;p&gt;The Ruby SAML library is for implementing the client side of a SAML authorization. In versions 1.18.0 and below, a denial-of-service vulnerability exists in ruby-saml even with the message_max_bytesize setting configured. The vulnerability occurs because the SAML response is validated for Base64 format prior to checking the message size, leading to potential resource exhaustion. This is fixed in version 1.18.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: ruby-saml, Ubuntu:Pro:18.04:LTS: ruby-saml, Ubuntu:Pro:20.04:LTS: ruby-saml, Ubuntu:Pro:22.04:LTS: ruby-saml, Ubuntu:Pro:24.04:LTS: ruby-saml&lt;/p&gt;
&lt;p&gt;The Ruby SAML library is for implementing the client side of a SAML authorization. In versions 1.18.0 and below, a denial-of-service vulnerability exists in ruby-saml even with the message_max_bytesize setting configured. The vulnerability occurs because the SAML response is validated for Base64 format prior to checking the message size, leading to potential resource exhaustion. This is fixed in version 1.18.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-54572</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-1686 — Ruby SAML: Schwachstelle ermöglicht Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1686</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Ruby SAML ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Ruby SAML ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1686</guid>
    </item>
  </channel>
</rss>
