Security Advisory

CVE-2025-48995

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-06-02 16:23:27
Last updated 2025-06-02 16:41:13
Assigner GitHub_M
State PUBLISHED

Description

SignXML is an implementation of the W3C XML Signature standard in Python. When verifying signatures with X509 certificate validation turned off and HMAC shared secret set (`signxml.XMLVerifier.verify(require_x509=False, hmac_key=...`), versions of SignXML prior to 4.0.4 are vulnerable to a potential timing attack. The verifier may leak information about the correct HMAC when comparing it with the user supplied hash, allowing users to reconstruct the correct HMAC for any data.