Логотип exploitDog
bind:CVE-2025-66578
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-66578

Количество 3

Количество 3

nvd логотип

CVE-2025-66578

2 месяца назад

xmlseclibs is a library written in PHP for working with XML Encryption and Signatures. Versions 3.1.3 contain an authentication bypass vulnerability due to a flaw in the libxml2 canonicalization process during document transformation. When libxml2’s canonicalization is invoked on an invalid XML input, it may return an empty string rather than a canonicalized node. xmlseclibs then proceeds to compute the DigestValue over this empty string, treating it as if canonicalization succeeded. This issue is fixed in version 3.1.4. Workarounds include treating canonicalization failures (exceptions or nil/empty outputs) as fatal and aborting validation, and/or adding explicit checks to reject when canonicalize returns nil/empty or raises errors.

CVSS3: 6
EPSS: Низкий
debian логотип

CVE-2025-66578

2 месяца назад

xmlseclibs is a library written in PHP for working with XML Encryption ...

CVSS3: 6
EPSS: Низкий
github логотип

GHSA-c4cc-x928-vjw9

2 месяца назад

robrichards/xmlseclibs has an Libxml2 Canonicalization error which can bypass Digest/Signature validation

CVSS3: 6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-66578

xmlseclibs is a library written in PHP for working with XML Encryption and Signatures. Versions 3.1.3 contain an authentication bypass vulnerability due to a flaw in the libxml2 canonicalization process during document transformation. When libxml2’s canonicalization is invoked on an invalid XML input, it may return an empty string rather than a canonicalized node. xmlseclibs then proceeds to compute the DigestValue over this empty string, treating it as if canonicalization succeeded. This issue is fixed in version 3.1.4. Workarounds include treating canonicalization failures (exceptions or nil/empty outputs) as fatal and aborting validation, and/or adding explicit checks to reject when canonicalize returns nil/empty or raises errors.

CVSS3: 6
0%
Низкий
2 месяца назад
debian логотип
CVE-2025-66578

xmlseclibs is a library written in PHP for working with XML Encryption ...

CVSS3: 6
0%
Низкий
2 месяца назад
github логотип
GHSA-c4cc-x928-vjw9

robrichards/xmlseclibs has an Libxml2 Canonicalization error which can bypass Digest/Signature validation

CVSS3: 6
0%
Низкий
2 месяца назад

Уязвимостей на страницу