CVE-2025-40934

XML-Sig versions 0.27 through 0.67 for Perl incorrectly validates XML files if signatures are omitted. An attacker can remove the signature from the XML document to make it pass the verification check. XML-Sig is a Perl module to validate signatures on XML files.  An unsigned XML file should return an error message.  The affected versions return true when attempting to validate an XML file that contains no signatures.
Configurations

No configuration.

History

28 Nov 2025, 19:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.3

26 Nov 2025, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-26 23:15

Updated : 2025-12-01 15:39


NVD link : CVE-2025-40934

Mitre link : CVE-2025-40934

CVE.ORG link : CVE-2025-40934


JSON object : View

Products Affected

No product.

CWE
CWE-347

Improper Verification of Cryptographic Signature