PT-2025-48197 · Xml-Sig · Xml::Sig

Gttds

·

Published

2025-11-26

·

Updated

2025-12-30

·

CVE-2025-40934

CVSS v3.1

9.3

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:N
Name of the Vulnerable Software and Affected Versions XML-Sig versions 0.27 through 0.67
Description The Perl module XML-Sig does not correctly validate XML files when signatures are absent. An attacker can remove a signature from an XML document, causing the verification check to pass incorrectly. An unsigned XML file should normally return an error, but the affected versions return a successful validation result when no signature is present.
Recommendations Update to a version of XML-Sig greater than 0.67.

Fix

Improper Verification of Cryptographic Signature

Weakness Enumeration

Related Identifiers

CVE-2025-40934

Affected Products

Xml::Sig