_get_signed_xml of the file lib/XML/Sig.pm. The manipulation of the argument ID results in insufficient verification of data authenticity.
This vulnerability is identified as CVE-2026-9487. The attack can be executed remotely. There is not any exploit available.
It is advisable to upgrade the affected component.
Intelligence View
⚡ tsecurity.de Intelligence
CVE-2026-9487 | XML::Sig up to 0.70 lib/XML/Sig.pm _get_signed_xml ID data authenticity (EUVD-2026-52270)
Reagiere als Erste:r — dein Feedback zählt!
A vulnerability categorized as critical has been discovered in XML::Sig up to 0.70. This affects the function
SOCIAL SHARE CARD GENERATOR