“In other words, it could be used for an account takeover attack.”
ruby-saml ran two XML parsers that disagreed about which signature they saw. One valid signature let an attacker log in as anyone. GitHub found it exploitable in GitLab. GitHub dropped ruby-saml in 2014 and only looked again because it considered going back.