CVE-2025-66567ruby-saml bypass after 1.12.4, PortSwigger Fragile Lock
What broke
PortSwigger's December 2025 research, "The Fragile Lock," showed that ruby-saml versions below 1.18.0, including 1.12.4 (the first patched line for the March bugs), still accepted forged SAML assertions. CVE-2025-66567 and CVE-2025-66568 are that pair. Fixed in ruby-saml 1.18.1.
Why it matters
A year of "we patched ruby-saml" tickets was not enough. Anyone who stopped at 1.12.4 stayed exposed through the 2025 holiday change freeze, which is exactly when identity incidents are hardest to staff.
What to do
- Pin ruby-saml >= 1.18.1. Reject 1.12.4 as "patched" in any SBOM or Dependabot baseline.
- If GitLab, omniauth-saml, or an internal Rails SP was on the 1.12 line in December 2025, assume the ACS was exploitable and review admin SSO logs for unexpected first-time NameIDs.
- Read the SAML 2.0 deep dive pitfalls section before you write the next custom verifier.
After you patch
A SAML bypass means the service provider accepted an assertion it should have rejected, so anyone who exploited it authenticated as a real user and left a normal-looking log line.
- Revoke every session issued by the affected service provider, then rotate its session signing keys. Patching stops new forgeries and does nothing about sessions already minted.
- Audit administrative accounts and group memberships for changes during the exposure window. Signing in as an administrator is the point of this class, and adding a second account is the standard persistence step.
- Rotate the identity provider signing certificate if the flaw involved signature validation, and confirm the service provider pins the expected certificate rather than trusting anything in the assertion.
- Check your own implementation for the same class: exact-match comparison on verification results, rejection of unexpected signature algorithms, and audience and recency checks on every assertion. See SAML 2.0 and SAML vs OIDC.
Sources
- NVD: CVE-2025-66567
- PortSwigger, "The Fragile Lock" (8 December 2025)
Related identity CVEs
Related on Start with Identity
- CVEruby-saml auth bypass, incomplete fix of CVE-2025-25292
The March 2025 ruby-saml patch did not close the parser differential. CVE-2025-54572 is the incomplete-fix follow-on: still a critical SSO impersonation if you
- CVEruby-saml 2024 auth bypass (ahacker1), still in the blast radius
The original 2024 ruby-saml authentication bypass (CVSS 10.0). It is outside the last twelve months, but every 2025 ruby-saml CVE is an incomplete-fix descendan
- CVEruby-saml companion signature-wrapping bypass
The pair to CVE-2025-25291. A second signature-wrapping path in ruby-saml lets an attacker forge assertions and impersonate any user. The March 2025 patch was l
- BlogFortinet's January SSO bypass hit boxes already patched for December's SAML bug
CVE-2026-24858 is the follow-on FortiCloud SSO SAML bypass. Devices patched for CVE-2025-59718 and 59719 were still exploitable. Actively exploited. CISA guidan
- GlossaryIdentity Federation
A trust relationship between identity providers and service providers that lets users authenticate once at their home IdP and access applications at the other p
- GlossaryService Provider (SP)
The application that consumes identity assertions from an IdP to grant the user access. In SAML it's the SP; in OIDC the equivalent is the Relying Party. The se
Technique
This CVE is an instance of Federation trust abuse and SAML forgery. A service provider that accepts a SAML assertion it should have rejected treats a forged identity as authenticated, because the failure sits in signature validation code, not in cryptography.