216.73.216.10

CVE-2025-40934

· Published 26/11/2025 23:15 · Modified 01/12/2025 15:39

Labels: CVE-2025-40934 2025-11-269b29abf9-4ab0-4765-b253-1875cd9b441eCVE-2025-40934CWE-347

Essential information

Published
26/11/2025 23:15
Modified
01/12/2025 15:39
Author
Creator
CVSS
9.3 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:N

CVSS metrics

Description

XML-Sig versions 0.27 through 0.67 for Perl incorrectly validates XML files if signatures are omitted. An attacker can remove the signature from the XML document to make it pass the verification check. XML-Sig is a Perl module to validate signatures on XML files.  An unsigned XML file should return an error message.  The affected versions return true when attempting to validate an XML file that contains no signatures.

NVD status

Status
Awaiting Analysis — CVE has been marked for Analysis. Normally once in this state the CVE will be analyzed by NVD staff within 24 hours.
Source
9b29abf9-4ab0-4765-b253-1875cd9b441e
NVD
View on NVD

References