Security: robrichards/xmlseclibs
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
Report a vulnerability-
XPath Injection in Transform Processing Enables Pre-Authentication Denial of Service in xmlseclibsGHSA-7mf5-fjj8-mvjc published
Aug 24, 2026 by robrichardsHigh -
RSA PKCS#1 v1.5 Bleichenbacher Padding Oracle via Distinguishable Decryption Errors in xmlseclibsGHSA-39hg-wfcm-v4wv published
Aug 24, 2026 by robrichardsModerate -
Timing Side-Channel in HMAC-SHA1 Signature Verification via Non-Constant-Time strcmp ComparisonGHSA-w5f2-cpgp-pg76 published
Aug 24, 2026 by robrichardsHigh -
Algorithm Substitution: RSA-to-HMAC Key Confusion Allows Signature Forgery via locateKey()GHSA-m5mw-mr39-66vp published
Aug 24, 2026 by robrichardsCritical -
XXE in decryptNode() via loadXML of attacker-controlled decrypted content (PHP < 8.0)GHSA-7hf8-fh6v-wmm6 published
Aug 24, 2026 by robrichardsModerate -
CBC Padding Oracle via Unvalidated ISO 10126 Unpadding Enables Decryption of Encrypted XML ContentGHSA-7h47-29x2-r2gc published
Aug 24, 2026 by robrichardsModerate -
Signature verification bypass via XML entity reference XPath hash skipGHSA-9wcx-p7hr-f935 published
Aug 24, 2026 by robrichardsLow -
Missing AES-GCM Authentication Tag Validation on Encrypted Nodes Allows for Unauthorized DecryptionGHSA-4v26-v6cg-g6f9 published
Mar 13, 2026 by robrichardsHigh -
Libxml2 Canonicalization error can bypass Digest/Signature validationGHSA-c4cc-x928-vjw9 published
Dec 8, 2025 by robrichardsModerate
Learn more about advisories related to robrichards/xmlseclibs in the GitHub Advisory Database