All 3 CVE vulnerabilities found in xml-crypto, with AI-generated Chinese analysis, references, and POCs.
Vendor: node-saml
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2025-29775 | xml-crypto Vulnerable to XML Signature Verification Bypass via DigestValue Comment CWE-347 | 9.8 | - | 2025-03-14 |
| CVE-2025-29774 | xml-crypto Vulnerable to XML Signature Verification Bypass via Multiple SignedInfo References CWE-347 | 8.8 | - | 2025-03-14 |
| CVE-2024-32962 | XML signature verification bypass due improper verification of signature / signature spoofing CWE-347 | 10.0 | Critical | 2024-05-02 |
All 3 known CVE vulnerabilities affecting xml-crypto with full Chinese analysis, references, and POCs where available.