signxml
Python XML Signature and XAdES library
Activity
- Latest release
- 2mo ago
- Total releases
- 90
- Cadence
- ~26 days
- Last 12 months
- 9
Reach
- Stars
- —
Details
- License
- unknown
- First release
- Sep 09, 2014
| Version | Released | |
|---|---|---|
5.1.0
minor
| ||
5.0.1
patch
| ||
5.0.0
major
| ||
4.5.1
minor
| ||
4.4.0
minor
| ||
4.3.1
patch
| ||
4.3.0
minor
| ||
4.2.2
patch
| ||
4.2.1
patch
| ||
4.2.0
minor
| ||
4.1.0
minor
| ||
4.0.5
patch
| ||
4.0.4
patch
| ||
4.0.3
patch
2 CVEs
CVE-2025-48994
PYSEC-2026-1921
GHSA-6vx8-pcwv-xhf4
Jul 07, 2026
SignXML's signature verification with HMAC is vulnerable to an algorithm confusion attack
Medium
Network
Low
None
None
When verifying signatures with X509 certificate validation turned off and HMAC shared secret set ( Starting with signxml 4.0.4, specifying Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 65 more Show less
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.6.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.4
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.6
2.3.0
2.4.0
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.2
2.9.0
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
4.0.4
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-48995
PYSEC-2026-1922
GHSA-gmhf-gg8w-jw42
Jul 07, 2026
SignXML's signature verification with HMAC is vulnerable to a timing attack
Medium
Network
Low
None
None
When verifying signatures with X509 certificate validation turned off and HMAC shared secret set ( Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 65 more Show less
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.6.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.4
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.6
2.3.0
2.4.0
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.2
2.9.0
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
4.0.4
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
4.0.2
patch
2 CVEs
CVE-2025-48994
PYSEC-2026-1921
GHSA-6vx8-pcwv-xhf4
Jul 07, 2026
SignXML's signature verification with HMAC is vulnerable to an algorithm confusion attack
Medium
Network
Low
None
None
When verifying signatures with X509 certificate validation turned off and HMAC shared secret set ( Starting with signxml 4.0.4, specifying Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 65 more Show less
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.6.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.4
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.6
2.3.0
2.4.0
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.2
2.9.0
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
4.0.4
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-48995
PYSEC-2026-1922
GHSA-gmhf-gg8w-jw42
Jul 07, 2026
SignXML's signature verification with HMAC is vulnerable to a timing attack
Medium
Network
Low
None
None
When verifying signatures with X509 certificate validation turned off and HMAC shared secret set ( Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 65 more Show less
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.6.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.4
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.6
2.3.0
2.4.0
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.2
2.9.0
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
4.0.4
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
4.0.1
patch
2 CVEs
CVE-2025-48994
PYSEC-2026-1921
GHSA-6vx8-pcwv-xhf4
Jul 07, 2026
SignXML's signature verification with HMAC is vulnerable to an algorithm confusion attack
Medium
Network
Low
None
None
When verifying signatures with X509 certificate validation turned off and HMAC shared secret set ( Starting with signxml 4.0.4, specifying Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 65 more Show less
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.6.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.4
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.6
2.3.0
2.4.0
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.2
2.9.0
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
4.0.4
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-48995
PYSEC-2026-1922
GHSA-gmhf-gg8w-jw42
Jul 07, 2026
SignXML's signature verification with HMAC is vulnerable to a timing attack
Medium
Network
Low
None
None
When verifying signatures with X509 certificate validation turned off and HMAC shared secret set ( Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 65 more Show less
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.6.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.4
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.6
2.3.0
2.4.0
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.2
2.9.0
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
4.0.4
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
4.0.0
major
2 CVEs
CVE-2025-48994
PYSEC-2026-1921
GHSA-6vx8-pcwv-xhf4
Jul 07, 2026
SignXML's signature verification with HMAC is vulnerable to an algorithm confusion attack
Medium
Network
Low
None
None
When verifying signatures with X509 certificate validation turned off and HMAC shared secret set ( Starting with signxml 4.0.4, specifying Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 65 more Show less
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.6.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.4
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.6
2.3.0
2.4.0
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.2
2.9.0
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
4.0.4
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-48995
PYSEC-2026-1922
GHSA-gmhf-gg8w-jw42
Jul 07, 2026
SignXML's signature verification with HMAC is vulnerable to a timing attack
Medium
Network
Low
None
None
When verifying signatures with X509 certificate validation turned off and HMAC shared secret set ( Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 65 more Show less
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.6.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.4
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.6
2.3.0
2.4.0
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.2
2.9.0
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
4.0.4
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
3.2.2
patch
2 CVEs
CVE-2025-48994
PYSEC-2026-1921
GHSA-6vx8-pcwv-xhf4
Jul 07, 2026
SignXML's signature verification with HMAC is vulnerable to an algorithm confusion attack
Medium
Network
Low
None
None
When verifying signatures with X509 certificate validation turned off and HMAC shared secret set ( Starting with signxml 4.0.4, specifying Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 65 more Show less
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.6.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.4
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.6
2.3.0
2.4.0
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.2
2.9.0
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
4.0.4
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-48995
PYSEC-2026-1922
GHSA-gmhf-gg8w-jw42
Jul 07, 2026
SignXML's signature verification with HMAC is vulnerable to a timing attack
Medium
Network
Low
None
None
When verifying signatures with X509 certificate validation turned off and HMAC shared secret set ( Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 65 more Show less
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.6.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.4
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.6
2.3.0
2.4.0
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.2
2.9.0
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
4.0.4
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
3.2.1
patch
2 CVEs
CVE-2025-48994
PYSEC-2026-1921
GHSA-6vx8-pcwv-xhf4
Jul 07, 2026
SignXML's signature verification with HMAC is vulnerable to an algorithm confusion attack
Medium
Network
Low
None
None
When verifying signatures with X509 certificate validation turned off and HMAC shared secret set ( Starting with signxml 4.0.4, specifying Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 65 more Show less
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.6.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.4
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.6
2.3.0
2.4.0
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.2
2.9.0
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
4.0.4
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-48995
PYSEC-2026-1922
GHSA-gmhf-gg8w-jw42
Jul 07, 2026
SignXML's signature verification with HMAC is vulnerable to a timing attack
Medium
Network
Low
None
None
When verifying signatures with X509 certificate validation turned off and HMAC shared secret set ( Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 65 more Show less
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.6.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.4
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.6
2.3.0
2.4.0
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.2
2.9.0
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
4.0.4
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
3.2.0
minor
2 CVEs
CVE-2025-48994
PYSEC-2026-1921
GHSA-6vx8-pcwv-xhf4
Jul 07, 2026
SignXML's signature verification with HMAC is vulnerable to an algorithm confusion attack
Medium
Network
Low
None
None
When verifying signatures with X509 certificate validation turned off and HMAC shared secret set ( Starting with signxml 4.0.4, specifying Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 65 more Show less
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.6.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.4
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.6
2.3.0
2.4.0
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.2
2.9.0
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
4.0.4
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-48995
PYSEC-2026-1922
GHSA-gmhf-gg8w-jw42
Jul 07, 2026
SignXML's signature verification with HMAC is vulnerable to a timing attack
Medium
Network
Low
None
None
When verifying signatures with X509 certificate validation turned off and HMAC shared secret set ( Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 65 more Show less
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.6.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.4
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.6
2.3.0
2.4.0
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.2
2.9.0
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
4.0.4
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
3.1.1
patch
2 CVEs
CVE-2025-48994
PYSEC-2026-1921
GHSA-6vx8-pcwv-xhf4
Jul 07, 2026
SignXML's signature verification with HMAC is vulnerable to an algorithm confusion attack
Medium
Network
Low
None
None
When verifying signatures with X509 certificate validation turned off and HMAC shared secret set ( Starting with signxml 4.0.4, specifying Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 65 more Show less
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.6.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.4
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.6
2.3.0
2.4.0
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.2
2.9.0
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
4.0.4
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-48995
PYSEC-2026-1922
GHSA-gmhf-gg8w-jw42
Jul 07, 2026
SignXML's signature verification with HMAC is vulnerable to a timing attack
Medium
Network
Low
None
None
When verifying signatures with X509 certificate validation turned off and HMAC shared secret set ( Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 65 more Show less
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.6.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.4
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.6
2.3.0
2.4.0
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.2
2.9.0
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
4.0.4
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
3.1.0
minor
2 CVEs
CVE-2025-48994
PYSEC-2026-1921
GHSA-6vx8-pcwv-xhf4
Jul 07, 2026
SignXML's signature verification with HMAC is vulnerable to an algorithm confusion attack
Medium
Network
Low
None
None
When verifying signatures with X509 certificate validation turned off and HMAC shared secret set ( Starting with signxml 4.0.4, specifying Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 65 more Show less
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.6.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.4
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.6
2.3.0
2.4.0
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.2
2.9.0
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
4.0.4
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-48995
PYSEC-2026-1922
GHSA-gmhf-gg8w-jw42
Jul 07, 2026
SignXML's signature verification with HMAC is vulnerable to a timing attack
Medium
Network
Low
None
None
When verifying signatures with X509 certificate validation turned off and HMAC shared secret set ( Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 65 more Show less
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.6.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.4
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.6
2.3.0
2.4.0
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.2
2.9.0
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
4.0.4
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
3.0.2
patch
2 CVEs
CVE-2025-48994
PYSEC-2026-1921
GHSA-6vx8-pcwv-xhf4
Jul 07, 2026
SignXML's signature verification with HMAC is vulnerable to an algorithm confusion attack
Medium
Network
Low
None
None
When verifying signatures with X509 certificate validation turned off and HMAC shared secret set ( Starting with signxml 4.0.4, specifying Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 65 more Show less
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.6.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.4
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.6
2.3.0
2.4.0
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.2
2.9.0
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
4.0.4
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-48995
PYSEC-2026-1922
GHSA-gmhf-gg8w-jw42
Jul 07, 2026
SignXML's signature verification with HMAC is vulnerable to a timing attack
Medium
Network
Low
None
None
When verifying signatures with X509 certificate validation turned off and HMAC shared secret set ( Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 65 more Show less
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.6.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.4
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.6
2.3.0
2.4.0
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.2
2.9.0
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
4.0.4
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
3.0.1
patch
2 CVEs
CVE-2025-48994
PYSEC-2026-1921
GHSA-6vx8-pcwv-xhf4
Jul 07, 2026
SignXML's signature verification with HMAC is vulnerable to an algorithm confusion attack
Medium
Network
Low
None
None
When verifying signatures with X509 certificate validation turned off and HMAC shared secret set ( Starting with signxml 4.0.4, specifying Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 65 more Show less
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.6.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.4
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.6
2.3.0
2.4.0
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.2
2.9.0
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
4.0.4
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-48995
PYSEC-2026-1922
GHSA-gmhf-gg8w-jw42
Jul 07, 2026
SignXML's signature verification with HMAC is vulnerable to a timing attack
Medium
Network
Low
None
None
When verifying signatures with X509 certificate validation turned off and HMAC shared secret set ( Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 65 more Show less
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.6.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.4
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.6
2.3.0
2.4.0
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.2
2.9.0
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
4.0.4
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
3.0.0
major
2 CVEs
CVE-2025-48994
PYSEC-2026-1921
GHSA-6vx8-pcwv-xhf4
Jul 07, 2026
SignXML's signature verification with HMAC is vulnerable to an algorithm confusion attack
Medium
Network
Low
None
None
When verifying signatures with X509 certificate validation turned off and HMAC shared secret set ( Starting with signxml 4.0.4, specifying Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 65 more Show less
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.6.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.4
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.6
2.3.0
2.4.0
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.2
2.9.0
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
4.0.4
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-48995
PYSEC-2026-1922
GHSA-gmhf-gg8w-jw42
Jul 07, 2026
SignXML's signature verification with HMAC is vulnerable to a timing attack
Medium
Network
Low
None
None
When verifying signatures with X509 certificate validation turned off and HMAC shared secret set ( Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 65 more Show less
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.6.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.4
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.6
2.3.0
2.4.0
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.2
2.9.0
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
4.0.4
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
2.10.1
patch
2 CVEs
CVE-2025-48994
PYSEC-2026-1921
GHSA-6vx8-pcwv-xhf4
Jul 07, 2026
SignXML's signature verification with HMAC is vulnerable to an algorithm confusion attack
Medium
Network
Low
None
None
When verifying signatures with X509 certificate validation turned off and HMAC shared secret set ( Starting with signxml 4.0.4, specifying Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 65 more Show less
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.6.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.4
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.6
2.3.0
2.4.0
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.2
2.9.0
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
4.0.4
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-48995
PYSEC-2026-1922
GHSA-gmhf-gg8w-jw42
Jul 07, 2026
SignXML's signature verification with HMAC is vulnerable to a timing attack
Medium
Network
Low
None
None
When verifying signatures with X509 certificate validation turned off and HMAC shared secret set ( Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 65 more Show less
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.6.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.4
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.6
2.3.0
2.4.0
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.2
2.9.0
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
4.0.4
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
2.10.0
minor
2 CVEs
CVE-2025-48994
PYSEC-2026-1921
GHSA-6vx8-pcwv-xhf4
Jul 07, 2026
SignXML's signature verification with HMAC is vulnerable to an algorithm confusion attack
Medium
Network
Low
None
None
When verifying signatures with X509 certificate validation turned off and HMAC shared secret set ( Starting with signxml 4.0.4, specifying Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 65 more Show less
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.6.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.4
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.6
2.3.0
2.4.0
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.2
2.9.0
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
4.0.4
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-48995
PYSEC-2026-1922
GHSA-gmhf-gg8w-jw42
Jul 07, 2026
SignXML's signature verification with HMAC is vulnerable to a timing attack
Medium
Network
Low
None
None
When verifying signatures with X509 certificate validation turned off and HMAC shared secret set ( Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 65 more Show less
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.6.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.4
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.6
2.3.0
2.4.0
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.2
2.9.0
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
4.0.4
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
2.9.0
minor
2 CVEs
CVE-2025-48994
PYSEC-2026-1921
GHSA-6vx8-pcwv-xhf4
Jul 07, 2026
SignXML's signature verification with HMAC is vulnerable to an algorithm confusion attack
Medium
Network
Low
None
None
When verifying signatures with X509 certificate validation turned off and HMAC shared secret set ( Starting with signxml 4.0.4, specifying Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 65 more Show less
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.6.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.4
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.6
2.3.0
2.4.0
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.2
2.9.0
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
4.0.4
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-48995
PYSEC-2026-1922
GHSA-gmhf-gg8w-jw42
Jul 07, 2026
SignXML's signature verification with HMAC is vulnerable to a timing attack
Medium
Network
Low
None
None
When verifying signatures with X509 certificate validation turned off and HMAC shared secret set ( Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 65 more Show less
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.6.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.4
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.6
2.3.0
2.4.0
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.2
2.9.0
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
4.0.4
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
2.8.2
patch
2 CVEs
CVE-2025-48994
PYSEC-2026-1921
GHSA-6vx8-pcwv-xhf4
Jul 07, 2026
SignXML's signature verification with HMAC is vulnerable to an algorithm confusion attack
Medium
Network
Low
None
None
When verifying signatures with X509 certificate validation turned off and HMAC shared secret set ( Starting with signxml 4.0.4, specifying Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 65 more Show less
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.6.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.4
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.6
2.3.0
2.4.0
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.2
2.9.0
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
4.0.4
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-48995
PYSEC-2026-1922
GHSA-gmhf-gg8w-jw42
Jul 07, 2026
SignXML's signature verification with HMAC is vulnerable to a timing attack
Medium
Network
Low
None
None
When verifying signatures with X509 certificate validation turned off and HMAC shared secret set ( Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 65 more Show less
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.6.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.4
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.6
2.3.0
2.4.0
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.2
2.9.0
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
4.0.4
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
2.8.1
patch
2 CVEs
CVE-2025-48994
PYSEC-2026-1921
GHSA-6vx8-pcwv-xhf4
Jul 07, 2026
SignXML's signature verification with HMAC is vulnerable to an algorithm confusion attack
Medium
Network
Low
None
None
When verifying signatures with X509 certificate validation turned off and HMAC shared secret set ( Starting with signxml 4.0.4, specifying Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 65 more Show less
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.6.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.4
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.6
2.3.0
2.4.0
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.2
2.9.0
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
4.0.4
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-48995
PYSEC-2026-1922
GHSA-gmhf-gg8w-jw42
Jul 07, 2026
SignXML's signature verification with HMAC is vulnerable to a timing attack
Medium
Network
Low
None
None
When verifying signatures with X509 certificate validation turned off and HMAC shared secret set ( Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 65 more Show less
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.6.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.4
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.6
2.3.0
2.4.0
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.2
2.9.0
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
4.0.4
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
2.8.0
minor
2 CVEs
CVE-2025-48994
PYSEC-2026-1921
GHSA-6vx8-pcwv-xhf4
Jul 07, 2026
SignXML's signature verification with HMAC is vulnerable to an algorithm confusion attack
Medium
Network
Low
None
None
When verifying signatures with X509 certificate validation turned off and HMAC shared secret set ( Starting with signxml 4.0.4, specifying Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 65 more Show less
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.6.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.4
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.6
2.3.0
2.4.0
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.2
2.9.0
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
4.0.4
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-48995
PYSEC-2026-1922
GHSA-gmhf-gg8w-jw42
Jul 07, 2026
SignXML's signature verification with HMAC is vulnerable to a timing attack
Medium
Network
Low
None
None
When verifying signatures with X509 certificate validation turned off and HMAC shared secret set ( Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 65 more Show less
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.6.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.4
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.6
2.3.0
2.4.0
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.2
2.9.0
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
4.0.4
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
2.7.3
patch
2 CVEs
CVE-2025-48994
PYSEC-2026-1921
GHSA-6vx8-pcwv-xhf4
Jul 07, 2026
SignXML's signature verification with HMAC is vulnerable to an algorithm confusion attack
Medium
Network
Low
None
None
When verifying signatures with X509 certificate validation turned off and HMAC shared secret set ( Starting with signxml 4.0.4, specifying Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 65 more Show less
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.6.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.4
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.6
2.3.0
2.4.0
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.2
2.9.0
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
4.0.4
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-48995
PYSEC-2026-1922
GHSA-gmhf-gg8w-jw42
Jul 07, 2026
SignXML's signature verification with HMAC is vulnerable to a timing attack
Medium
Network
Low
None
None
When verifying signatures with X509 certificate validation turned off and HMAC shared secret set ( Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 65 more Show less
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.6.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.4
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.6
2.3.0
2.4.0
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.2
2.9.0
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
4.0.4
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
2.7.2
patch
2 CVEs
CVE-2025-48994
PYSEC-2026-1921
GHSA-6vx8-pcwv-xhf4
Jul 07, 2026
SignXML's signature verification with HMAC is vulnerable to an algorithm confusion attack
Medium
Network
Low
None
None
When verifying signatures with X509 certificate validation turned off and HMAC shared secret set ( Starting with signxml 4.0.4, specifying Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 65 more Show less
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.6.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.4
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.6
2.3.0
2.4.0
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.2
2.9.0
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
4.0.4
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-48995
PYSEC-2026-1922
GHSA-gmhf-gg8w-jw42
Jul 07, 2026
SignXML's signature verification with HMAC is vulnerable to a timing attack
Medium
Network
Low
None
None
When verifying signatures with X509 certificate validation turned off and HMAC shared secret set ( Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 65 more Show less
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.6.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.4
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.6
2.3.0
2.4.0
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.2
2.9.0
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
4.0.4
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
2.7.1
patch
2 CVEs
CVE-2025-48994
PYSEC-2026-1921
GHSA-6vx8-pcwv-xhf4
Jul 07, 2026
SignXML's signature verification with HMAC is vulnerable to an algorithm confusion attack
Medium
Network
Low
None
None
When verifying signatures with X509 certificate validation turned off and HMAC shared secret set ( Starting with signxml 4.0.4, specifying Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 65 more Show less
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.6.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.4
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.6
2.3.0
2.4.0
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.2
2.9.0
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
4.0.4
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-48995
PYSEC-2026-1922
GHSA-gmhf-gg8w-jw42
Jul 07, 2026
SignXML's signature verification with HMAC is vulnerable to a timing attack
Medium
Network
Low
None
None
When verifying signatures with X509 certificate validation turned off and HMAC shared secret set ( Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 65 more Show less
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.6.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.4
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.6
2.3.0
2.4.0
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.2
2.9.0
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
4.0.4
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
2.7.0
minor
2 CVEs
CVE-2025-48994
PYSEC-2026-1921
GHSA-6vx8-pcwv-xhf4
Jul 07, 2026
SignXML's signature verification with HMAC is vulnerable to an algorithm confusion attack
Medium
Network
Low
None
None
When verifying signatures with X509 certificate validation turned off and HMAC shared secret set ( Starting with signxml 4.0.4, specifying Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 65 more Show less
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.6.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.4
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.6
2.3.0
2.4.0
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.2
2.9.0
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
4.0.4
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-48995
PYSEC-2026-1922
GHSA-gmhf-gg8w-jw42
Jul 07, 2026
SignXML's signature verification with HMAC is vulnerable to a timing attack
Medium
Network
Low
None
None
When verifying signatures with X509 certificate validation turned off and HMAC shared secret set ( Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 65 more Show less
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.6.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.4
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.6
2.3.0
2.4.0
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.2
2.9.0
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
4.0.4
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
2.6.0
minor
2 CVEs
CVE-2025-48994
PYSEC-2026-1921
GHSA-6vx8-pcwv-xhf4
Jul 07, 2026
SignXML's signature verification with HMAC is vulnerable to an algorithm confusion attack
Medium
Network
Low
None
None
When verifying signatures with X509 certificate validation turned off and HMAC shared secret set ( Starting with signxml 4.0.4, specifying Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 65 more Show less
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.6.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.4
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.6
2.3.0
2.4.0
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.2
2.9.0
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
4.0.4
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-48995
PYSEC-2026-1922
GHSA-gmhf-gg8w-jw42
Jul 07, 2026
SignXML's signature verification with HMAC is vulnerable to a timing attack
Medium
Network
Low
None
None
When verifying signatures with X509 certificate validation turned off and HMAC shared secret set ( Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 65 more Show less
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.6.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.4
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.6
2.3.0
2.4.0
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.2
2.9.0
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
4.0.4
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
2.5.2
minor
2 CVEs
CVE-2025-48994
PYSEC-2026-1921
GHSA-6vx8-pcwv-xhf4
Jul 07, 2026
SignXML's signature verification with HMAC is vulnerable to an algorithm confusion attack
Medium
Network
Low
None
None
When verifying signatures with X509 certificate validation turned off and HMAC shared secret set ( Starting with signxml 4.0.4, specifying Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 65 more Show less
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.6.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.4
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.6
2.3.0
2.4.0
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.2
2.9.0
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
4.0.4
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-48995
PYSEC-2026-1922
GHSA-gmhf-gg8w-jw42
Jul 07, 2026
SignXML's signature verification with HMAC is vulnerable to a timing attack
Medium
Network
Low
None
None
When verifying signatures with X509 certificate validation turned off and HMAC shared secret set ( Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 65 more Show less
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.6.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.4
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.6
2.3.0
2.4.0
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.2
2.9.0
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
4.0.4
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
2.4.0
minor
2 CVEs
CVE-2025-48994
PYSEC-2026-1921
GHSA-6vx8-pcwv-xhf4
Jul 07, 2026
SignXML's signature verification with HMAC is vulnerable to an algorithm confusion attack
Medium
Network
Low
None
None
When verifying signatures with X509 certificate validation turned off and HMAC shared secret set ( Starting with signxml 4.0.4, specifying Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 65 more Show less
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.6.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.4
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.6
2.3.0
2.4.0
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.2
2.9.0
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
4.0.4
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-48995
PYSEC-2026-1922
GHSA-gmhf-gg8w-jw42
Jul 07, 2026
SignXML's signature verification with HMAC is vulnerable to a timing attack
Medium
Network
Low
None
None
When verifying signatures with X509 certificate validation turned off and HMAC shared secret set ( Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 65 more Show less
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.6.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.4
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.6
2.3.0
2.4.0
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.2
2.9.0
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
4.0.4
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
2.3.0
minor
2 CVEs
CVE-2025-48994
PYSEC-2026-1921
GHSA-6vx8-pcwv-xhf4
Jul 07, 2026
SignXML's signature verification with HMAC is vulnerable to an algorithm confusion attack
Medium
Network
Low
None
None
When verifying signatures with X509 certificate validation turned off and HMAC shared secret set ( Starting with signxml 4.0.4, specifying Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 65 more Show less
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.6.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.4
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.6
2.3.0
2.4.0
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.2
2.9.0
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
4.0.4
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-48995
PYSEC-2026-1922
GHSA-gmhf-gg8w-jw42
Jul 07, 2026
SignXML's signature verification with HMAC is vulnerable to a timing attack
Medium
Network
Low
None
None
When verifying signatures with X509 certificate validation turned off and HMAC shared secret set ( Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 65 more Show less
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.6.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.4
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.6
2.3.0
2.4.0
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.2
2.9.0
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
4.0.4
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
2.2.6
patch
2 CVEs
CVE-2025-48994
PYSEC-2026-1921
GHSA-6vx8-pcwv-xhf4
Jul 07, 2026
SignXML's signature verification with HMAC is vulnerable to an algorithm confusion attack
Medium
Network
Low
None
None
When verifying signatures with X509 certificate validation turned off and HMAC shared secret set ( Starting with signxml 4.0.4, specifying Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 65 more Show less
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.6.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.4
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.6
2.3.0
2.4.0
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.2
2.9.0
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
4.0.4
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-48995
PYSEC-2026-1922
GHSA-gmhf-gg8w-jw42
Jul 07, 2026
SignXML's signature verification with HMAC is vulnerable to a timing attack
Medium
Network
Low
None
None
When verifying signatures with X509 certificate validation turned off and HMAC shared secret set ( Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 65 more Show less
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.6.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.4
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.6
2.3.0
2.4.0
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.2
2.9.0
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
4.0.4
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
2.2.4
patch
2 CVEs
CVE-2025-48994
PYSEC-2026-1921
GHSA-6vx8-pcwv-xhf4
Jul 07, 2026
SignXML's signature verification with HMAC is vulnerable to an algorithm confusion attack
Medium
Network
Low
None
None
When verifying signatures with X509 certificate validation turned off and HMAC shared secret set ( Starting with signxml 4.0.4, specifying Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 65 more Show less
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.6.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.4
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.6
2.3.0
2.4.0
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.2
2.9.0
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
4.0.4
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-48995
PYSEC-2026-1922
GHSA-gmhf-gg8w-jw42
Jul 07, 2026
SignXML's signature verification with HMAC is vulnerable to a timing attack
Medium
Network
Low
None
None
When verifying signatures with X509 certificate validation turned off and HMAC shared secret set ( Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 65 more Show less
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.6.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.4
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.6
2.3.0
2.4.0
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.2
2.9.0
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
4.0.4
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
2.2.3
patch
2 CVEs
CVE-2025-48994
PYSEC-2026-1921
GHSA-6vx8-pcwv-xhf4
Jul 07, 2026
SignXML's signature verification with HMAC is vulnerable to an algorithm confusion attack
Medium
Network
Low
None
None
When verifying signatures with X509 certificate validation turned off and HMAC shared secret set ( Starting with signxml 4.0.4, specifying Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 65 more Show less
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.6.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.4
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.6
2.3.0
2.4.0
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.2
2.9.0
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
4.0.4
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-48995
PYSEC-2026-1922
GHSA-gmhf-gg8w-jw42
Jul 07, 2026
SignXML's signature verification with HMAC is vulnerable to a timing attack
Medium
Network
Low
None
None
When verifying signatures with X509 certificate validation turned off and HMAC shared secret set ( Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 65 more Show less
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.6.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.4
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.6
2.3.0
2.4.0
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.2
2.9.0
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
4.0.4
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
2.2.2
patch
2 CVEs
CVE-2025-48994
PYSEC-2026-1921
GHSA-6vx8-pcwv-xhf4
Jul 07, 2026
SignXML's signature verification with HMAC is vulnerable to an algorithm confusion attack
Medium
Network
Low
None
None
When verifying signatures with X509 certificate validation turned off and HMAC shared secret set ( Starting with signxml 4.0.4, specifying Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 65 more Show less
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.6.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.4
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.6
2.3.0
2.4.0
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.2
2.9.0
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
4.0.4
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-48995
PYSEC-2026-1922
GHSA-gmhf-gg8w-jw42
Jul 07, 2026
SignXML's signature verification with HMAC is vulnerable to a timing attack
Medium
Network
Low
None
None
When verifying signatures with X509 certificate validation turned off and HMAC shared secret set ( Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 65 more Show less
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.6.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.4
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.6
2.3.0
2.4.0
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.2
2.9.0
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
4.0.4
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
2.2.1
patch
2 CVEs
CVE-2025-48994
PYSEC-2026-1921
GHSA-6vx8-pcwv-xhf4
Jul 07, 2026
SignXML's signature verification with HMAC is vulnerable to an algorithm confusion attack
Medium
Network
Low
None
None
When verifying signatures with X509 certificate validation turned off and HMAC shared secret set ( Starting with signxml 4.0.4, specifying Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 65 more Show less
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.6.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.4
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.6
2.3.0
2.4.0
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.2
2.9.0
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
4.0.4
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-48995
PYSEC-2026-1922
GHSA-gmhf-gg8w-jw42
Jul 07, 2026
SignXML's signature verification with HMAC is vulnerable to a timing attack
Medium
Network
Low
None
None
When verifying signatures with X509 certificate validation turned off and HMAC shared secret set ( Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 65 more Show less
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.6.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.4
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.6
2.3.0
2.4.0
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.2
2.9.0
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
4.0.4
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
2.2.0
minor
2 CVEs
CVE-2025-48994
PYSEC-2026-1921
GHSA-6vx8-pcwv-xhf4
Jul 07, 2026
SignXML's signature verification with HMAC is vulnerable to an algorithm confusion attack
Medium
Network
Low
None
None
When verifying signatures with X509 certificate validation turned off and HMAC shared secret set ( Starting with signxml 4.0.4, specifying Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 65 more Show less
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.6.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.4
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.6
2.3.0
2.4.0
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.2
2.9.0
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
4.0.4
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-48995
PYSEC-2026-1922
GHSA-gmhf-gg8w-jw42
Jul 07, 2026
SignXML's signature verification with HMAC is vulnerable to a timing attack
Medium
Network
Low
None
None
When verifying signatures with X509 certificate validation turned off and HMAC shared secret set ( Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 65 more Show less
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.6.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.4
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.6
2.3.0
2.4.0
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.2
2.9.0
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
4.0.4
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
2.1.4
minor
2 CVEs
CVE-2025-48994
PYSEC-2026-1921
GHSA-6vx8-pcwv-xhf4
Jul 07, 2026
SignXML's signature verification with HMAC is vulnerable to an algorithm confusion attack
Medium
Network
Low
None
None
When verifying signatures with X509 certificate validation turned off and HMAC shared secret set ( Starting with signxml 4.0.4, specifying Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 65 more Show less
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.6.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.4
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.6
2.3.0
2.4.0
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.2
2.9.0
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
4.0.4
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-48995
PYSEC-2026-1922
GHSA-gmhf-gg8w-jw42
Jul 07, 2026
SignXML's signature verification with HMAC is vulnerable to a timing attack
Medium
Network
Low
None
None
When verifying signatures with X509 certificate validation turned off and HMAC shared secret set ( Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 65 more Show less
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.6.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.4
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.6
2.3.0
2.4.0
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.2
2.9.0
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
4.0.4
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
2.0.0
major
2 CVEs
CVE-2025-48994
PYSEC-2026-1921
GHSA-6vx8-pcwv-xhf4
Jul 07, 2026
SignXML's signature verification with HMAC is vulnerable to an algorithm confusion attack
Medium
Network
Low
None
None
When verifying signatures with X509 certificate validation turned off and HMAC shared secret set ( Starting with signxml 4.0.4, specifying Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 65 more Show less
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.6.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.4
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.6
2.3.0
2.4.0
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.2
2.9.0
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
4.0.4
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-48995
PYSEC-2026-1922
GHSA-gmhf-gg8w-jw42
Jul 07, 2026
SignXML's signature verification with HMAC is vulnerable to a timing attack
Medium
Network
Low
None
None
When verifying signatures with X509 certificate validation turned off and HMAC shared secret set ( Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 65 more Show less
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.6.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.4
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.6
2.3.0
2.4.0
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.2
2.9.0
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
4.0.4
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
1.0.2
patch
2 CVEs
CVE-2025-48994
PYSEC-2026-1921
GHSA-6vx8-pcwv-xhf4
Jul 07, 2026
SignXML's signature verification with HMAC is vulnerable to an algorithm confusion attack
Medium
Network
Low
None
None
When verifying signatures with X509 certificate validation turned off and HMAC shared secret set ( Starting with signxml 4.0.4, specifying Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 65 more Show less
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.6.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.4
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.6
2.3.0
2.4.0
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.2
2.9.0
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
4.0.4
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-48995
PYSEC-2026-1922
GHSA-gmhf-gg8w-jw42
Jul 07, 2026
SignXML's signature verification with HMAC is vulnerable to a timing attack
Medium
Network
Low
None
None
When verifying signatures with X509 certificate validation turned off and HMAC shared secret set ( Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 65 more Show less
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.6.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.4
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.6
2.3.0
2.4.0
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.2
2.9.0
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
4.0.4
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
1.0.1
patch
2 CVEs
CVE-2025-48994
PYSEC-2026-1921
GHSA-6vx8-pcwv-xhf4
Jul 07, 2026
SignXML's signature verification with HMAC is vulnerable to an algorithm confusion attack
Medium
Network
Low
None
None
When verifying signatures with X509 certificate validation turned off and HMAC shared secret set ( Starting with signxml 4.0.4, specifying Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 65 more Show less
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.6.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.4
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.6
2.3.0
2.4.0
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.2
2.9.0
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
4.0.4
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-48995
PYSEC-2026-1922
GHSA-gmhf-gg8w-jw42
Jul 07, 2026
SignXML's signature verification with HMAC is vulnerable to a timing attack
Medium
Network
Low
None
None
When verifying signatures with X509 certificate validation turned off and HMAC shared secret set ( Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 65 more Show less
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.6.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.4
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.6
2.3.0
2.4.0
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.2
2.9.0
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
4.0.4
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
1.0.0
major
2 CVEs
CVE-2025-48994
PYSEC-2026-1921
GHSA-6vx8-pcwv-xhf4
Jul 07, 2026
SignXML's signature verification with HMAC is vulnerable to an algorithm confusion attack
Medium
Network
Low
None
None
When verifying signatures with X509 certificate validation turned off and HMAC shared secret set ( Starting with signxml 4.0.4, specifying Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 65 more Show less
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.6.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.4
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.6
2.3.0
2.4.0
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.2
2.9.0
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
4.0.4
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-48995
PYSEC-2026-1922
GHSA-gmhf-gg8w-jw42
Jul 07, 2026
SignXML's signature verification with HMAC is vulnerable to a timing attack
Medium
Network
Low
None
None
When verifying signatures with X509 certificate validation turned off and HMAC shared secret set ( Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 65 more Show less
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.6.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.4
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.6
2.3.0
2.4.0
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.2
2.9.0
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
4.0.4
References
Updated Jul 07, 2026 · Source: OSV.dev |