Junglewise Threat Intelligence

CVE-2025-29774: xml-crypto XML signature verification bypass via multiple SignedInfo references

CVE-2025-29774 · Severity: medium · CVSS 4 · Published 2025-03-14

Technologies: Xml-Crypto.

Executive brief

xml-crypto is a library used to verify digitally signed XML documents, which are commonly used in authentication systems like SAML. An attacker can exploit this vulnerability to forge or modify signed XML messages in ways that still pass verification checks, potentially allowing them to escalate privileges, bypass access controls, or impersonate other users in systems that depend on XML signature validation.

Technical details

The vulnerability is an improper cryptographic signature verification issue (CWE-347) affecting xml-crypto versions 6.0.0 and earlier. An attacker can inject multiple SignedInfo elements within a single Signature node—the verification logic processes only one while an attacker crafts a forged reference with a fake digest value in a nested SignedInfo element. This allows the attacker to modify signed XML documents (e.g., SAML assertions) while the signature still validates. The attack requires network access to send modified signed XML payloads but no authentication or special privileges. Patches are available: version 6.0.1 for v6.x, 3.2.1 for v3.x, and 2.1.6 for v2.x.

Affected products

  • xml-crypto xml-crypto <=6.0.0

Timeline

  • 2025-03-14: disclosed
  • 2025-03-14: patched: Version 6.0.1, 3.2.1, 2.1.6 released

References