timlegge XML::Sig是timlegge个人开发者的一款处理XML数字签名的Perl模块。 timlegge XML::Sig 0.29版本至0.72之前版本存在加密问题漏洞,该漏洞源于签名验证逻辑不完善,在lib/XML/Sig.pm中的verify函数中,当所有签名在摘要或密钥检查前被跳过时,无条件返回1,可能导致攻击者绕过签名验证。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-18108 | Net::SAML2 versions before 0.86 for Perl allow authentication bypass because _verify_encry | |
| CVE-2026-18092 | Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass via XML signatur | |
| CVE-2026-18089 | Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass by verifying res | |
| CVE-2026-9390 | XML::Sig versions before 0.71 for Perl allow XPath injection in ID lookup | |
| CVE-2026-9487 | XML::Sig versions before 0.71 for Perl allow signature wrapping via duplicate ID |
No comments yet