top of page
perceptive_background_267k.jpg

xml-security is a library that implements XML signatures and encryption. Prior to versions 2.3.1 and 1.13.9, XML nodes encrypted with either aes-128-gcm, aes-19…

Published:

15 maart 2026 om 23:00:00

Alert date:

16 maart 2026 om 16:21:26

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Supply Chain & Dependencies

The xml-security library has a vulnerability in versions prior to 2.3.1 and 1.13.9 where XML nodes encrypted with AES-GCM algorithms (aes-128-gcm, aes-192-gcm, or aes-256-gcm) lack proper validation of authentication tag length. This flaw allows attackers to brute-force authentication tags, recover GHASH keys, decrypt encrypted nodes, and forge arbitrary ciphertexts without knowing the encryption key. The vulnerability affects XML signatures and encryption implementations and has been patched in versions 2.3.1 and 1.13.9.

Technical details

Mitigation steps:

Affected products:

xml-security library

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page