MEDIUMPyPI
GHSA-6vx8-pcwv-xhf4· CVE-2025-48994, PYSEC-2026-1921SignXML's signature verification with HMAC is vulnerable to an algorithm confusion attack
Modified: 7/7/2026
package
pkg:pypi/signxml
SignXML's signature verification with HMAC is vulnerable to an algorithm confusion attack
Modified: 7/7/2026
SignXML's signature verification with HMAC is vulnerable to a timing attack
Modified: 7/7/2026
SignXML's signature verification with HMAC is vulnerable to an algorithm confusion attack
Modified: 7/7/2026
SignXML's signature verification with HMAC is vulnerable to a timing attack
Modified: 7/7/2026