timlegge XML::Sig是timlegge个人开发者的一款处理XML数字签名的Perl模块。 TIMLEGGE XML::Sig 0.71之前版本存在加密问题漏洞,该漏洞源于使用XPath表达式解析SignedInfo Reference/@URI时仅返回第一个匹配节点,未检测重复ID,导致签名包装攻击,在SAML2上下文中可能使断言内容受攻击者控制。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-18108 | Net::SAML2 versions before 0.86 for Perl allow authentication bypass because _verify_encry | |
| CVE-2026-18092 | Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass via XML signatur | |
| CVE-2026-18089 | Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass by verifying res | |
| CVE-2026-9390 | XML::Sig versions before 0.71 for Perl allow XPath injection in ID lookup | |
| CVE-2026-18568 | XML::Sig versions from 0.29 before 0.72 for Perl allow signature verification bypass becau |
No comments yet