Security Advisories (1)
CVE-2026-18568 (2026-08-03)

XML::Sig versions from 0.29 before 0.72 for Perl allow signature verification bypass because verify returns true when every signature was skipped before any cryptographic check. verify in lib/XML/Sig.pm counts the `//dsig:Signature` elements into `$numsigs` and iterates over them, but two paths reach `next` before any digest or key check runs: a `SignedInfo/Reference/@URI` that resolves to no element while `$numsigs` is greater than 1, and, when `id_attr` is set, a reference that does not match the requested ID. The loop records nothing about what it checked, so when every signature takes one of those paths control reaches the unconditional `return 1` that ends verify. Two `Signature` elements whose Reference URI names an ID that no element carries is enough, as is one such element combined with `id_attr`. Any caller that passes untrusted XML to verify can receive a true return for a document in which no digest and no signature value was checked; a `cert` or `cert_text` trust anchor does not change this, because no key check runs. Versions up to 0.28 use an XML::XPath based verify that has no such skip and are not affected.

Changes for version 0.71 - 2026-07-30

  • Notable Changes
    • Security Fixes CVE-2026-9487 and CVE-2026-9390 CVE-2026-9390 enforces a subset of the characters allowed in an ID CVE-2026-9487 rejects signature checking if the ID references multiple nodes
  • Change Log
    • 7ac376f Update the release to use sigstore for signing
    • 7385a2a Update contact email address (replace cpan.org)
    • c0dd9f5 Update the build items dependencies and version
    • e59c13b Document the allowed characters in an ID
    • 4976bde Reject Duplicate IDs in XML document (CVE-2026-9487)
    • ef7a52b Fix some invalid characters in the array
    • f92a5b5 UTF8 in XML needs to be encoded to avoid Wide character errors
    • 9f54cb8 Add a mailmap file
    • a85aad2 improve the regex
    • 69ad2b4 Enforce the ID format as per the specification Reject any XML ids with invalid characters (CVE-2026-9390)
    • abd726a use instead of ->{parser} when called multiple times
    • 92970ff _load_key should not return anything
    • 1532383 v0.70

Documentation

Modules

XML::Sig - A toolkit to help sign and verify XML Digital Signatures