# The Fragile Lock: Novel Bypasses For SAML Authentication

DevFeed: [The Fragile Lock: Novel Bypasses For SAML Authentication](<https://devfeed.tech/articles/the-fragile-lock-novel-bypasses-for-saml-authentication-7703.md>)

Original publisher: [Read original article](<https://portswigger.net/research/the-fragile-lock>)

Author: Zakhar Fedotkin

Published: 2025-12-10T12:32:00Z

Content type: article

Language: en

Sources: [PortSwigger Research](<https://devfeed.tech/sources/portswigger-research.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [attacks](<https://devfeed.tech/tags/attacks.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [php](<https://devfeed.tech/tags/php.md>), [ruby](<https://devfeed.tech/tags/ruby.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

## AI overview

The article describes novel XML Signature Wrapping attacks that exploit parser inconsistencies to bypass SAML authentication in Ruby and PHP ecosystems.

## Source excerpt

TLDR This post shows how to achieve a full authentication bypass in the Ruby and PHP SAML ecosystem by exploiting several parser-level inconsistencies: including attribute pollution, namespace confusi