Collected research
The Fragile Lock: Novel Bypasses For SAML Authentication
Parser inconsistencies between REXML, Nokogiri and libxml2 let an attacker forge SAML responses: attribute pollution, namespace confusion via the reserved xml prefix, and a canonicalisation failure that makes the digest cover an empty string. Any identity-provider-signed XML then bypasses signature validation and grants login as any user.
Record
- Researcher
- Zakhar Fedotkin
- Published by
- PortSwigger Research
- Date
- Topic
- Identity
In the archive
Related sources
- Black Hat slides Whitepaper
- XSW exploitation extension
- Ruby-SAML disclosure announcement
- Black Hat Europe 2025 | The Fragile Lock: Novel Bypasses For SAML Authentication
Tags
This page is the archive's own catalogue record. The research is the work of Zakhar Fedotkin, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .