Description
XML::Sig versions before 0.71 for Perl allow signature wrapping via duplicate ID.

_get_signed_xml() in lib/XML/Sig.pm, called from verify(), resolves the SignedInfo Reference/@URI to a node with the XPath expression "//*[@ID='$id']" and returns the first node of the resulting node set. A document in which two elements share that ID value is accepted: the digest and signature are checked against whichever element comes first in document order, and the duplicate is not detected.

Such a document verifies successfully while an application that resolves the same ID independently can read the second, attacker supplied element; in a SAML2 context this places the contents of an Assertion under attacker control.
Published: 2026-08-03
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability exists in XML::Sig versions prior to 0.71, where the verification routine returns the first node matching a duplicate ID and accepts the document. This allows an attacker to craft an XML payload with two elements sharing an ID, so the original signed content is validated against the first element while the application may later read the second, attacker‑supplied element. In a SAML2 implementation this permits the attacker to replace the signed Assertion content, potentially granting unauthorized access or exfiltrating sensitive data.

Affected Systems

The affected product is XML::Sig for Perl, distributed by the TIMLEGGE vendor. All releases prior to 0.71 are vulnerable; version 0.71 and later contain the fix.

Risk and Exploitability

The CVSS score is 9.1, indicating a critical severity, and the EPSS score is not available. The vulnerability is not listed in CISA’s KEV catalog, indicating no known active exploitation at the time of analysis. Nevertheless, the flaw allows an attacker to supply a malicious signed XML document that passes verification, a high‑impact attack if the application relies on the signed Assertion for authentication or authorization. The vulnerability can be exploited by any party capable of forming the XML payload; therefore the risk level is moderate to high, especially in environments where SAML assertions are used frequently.

Generated by OpenCVE AI on August 4, 2026 at 10:23 UTC.

Remediation

Vendor Solution

Upgrade to version 0.71


Vendor Workaround

Signing the outermost <samlp:Response> element rather than only the inner <saml:Assertion> reduces exposure, but does not prevent wrapping variants in which the duplicate ID is introduced outside the signed element. Upgrading to 0.71 is the complete fix.


OpenCVE Recommended Actions

  • Upgrade XML::Sig to version 0.71 or later.
  • If immediate upgrade is not possible, modify the signing logic to sign the outermost <samlp:Response> element instead of only the inner <saml:Assertion>, which reduces but does not eliminate the risk of wrapping with a duplicate ID introduced outside the signed scope.
  • After applying a patch or workaround, audit the XML processing logic to ensure that duplicate IDs are rejected or that the application validates the signed element’s ID against the expected value.

Generated by OpenCVE AI on August 4, 2026 at 10:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 03 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Timlegge
Timlegge xml::sig
Vendors & Products Timlegge
Timlegge xml::sig

Mon, 03 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
Description XML::Sig versions before 0.71 for Perl allow signature wrapping via duplicate ID. _get_signed_xml() in lib/XML/Sig.pm, called from verify(), resolves the SignedInfo Reference/@URI to a node with the XPath expression "//*[@ID='$id']" and returns the first node of the resulting node set. A document in which two elements share that ID value is accepted: the digest and signature are checked against whichever element comes first in document order, and the duplicate is not detected. Such a document verifies successfully while an application that resolves the same ID independently can read the second, attacker supplied element; in a SAML2 context this places the contents of an Assertion under attacker control.
Title XML::Sig versions before 0.71 for Perl allow signature wrapping via duplicate ID
Weaknesses CWE-347
References

cve-icon MITRE

Status: PUBLISHED

Assigner: CPANSec

Published:

Updated: 2026-08-03T19:59:47.580Z

Reserved: 2026-05-24T13:47:37.954Z

Link: CVE-2026-9487

cve-icon Vulnrichment

Updated: 2026-08-03T19:59:42.866Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-03T14:16:31.110

Modified: 2026-08-05T14:57:50.460

Link: CVE-2026-9487

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T10:30:07Z

Weaknesses
  • CWE-347

    Improper Verification of Cryptographic Signature