VYPR

XML-Sig

by Perl Foundation

CVEs (3)

  • CVE-2026-18568Aug 3, 2026
    risk 0.00cvss epss 0.00

    XML::Sig versions from 0.29 before 0.72 for Perl allow signature verification bypass because verify returns true when every signature was skipped before any cryptographic check. verify in lib/XML/Sig.pm counts the `//dsig:Signature` elements into `$numsigs` and iterates over…

  • CVE-2026-9487Aug 3, 2026
    risk 0.00cvss epss 0.00

    XML::Sig versions before 0.71 for Perl allow signature wrapping via duplicate ID. _get_signed_xml() in lib/XML/Sig.pm, called from verify(), resolves the SignedInfo Reference/@URI to a node with the XPath expression "//*[@ID='$id']" and returns the first node of the resulting…

  • CVE-2025-40934CriNov 26, 2025
    risk 0.00cvss 9.3epss 0.00

    XML-Sig versions 0.27 through 0.67 for Perl incorrectly validates XML files if signatures are omitted. An attacker can remove the signature from the XML document to make it pass the verification check. XML-Sig is a Perl module to validate signatures on XML files.  An unsigned…