CVE-2026-9390: XML::Sig versions before 0.71 for Perl allow XPath injection in ID lookup
Timothy Legge 03 Aug 2026 13:11 UTC
========================================================================
CVE-2026-9390 CPAN Security Group
========================================================================
CVE ID: CVE-2026-9390
Distribution: XML-Sig
Versions: before 0.71
MetaCPAN: https://metacpan.org/dist/XML-Sig
VCS Repo: https://github.com/perl-net-saml2/perl-XML-Sig
XML::Sig versions before 0.71 for Perl allow XPath injection in ID
lookup
Description
-----------
XML::Sig versions before 0.71 for Perl allow XPath injection in ID
lookup.
verify() and _get_signed_xml() in lib/XML/Sig.pm build XPath
expressions by concatenating the SignedInfo/Reference/@URI value read
from the document being verified. The value is neither escaped nor
checked against the NCName grammar that XML requires of an ID, so a URI
containing a single quote closes the string literal in the generated
expression and appends arbitrary XPath operators.
A crafted URI can make the lookup match elements the reference does not
name, or every element in the document, so which node is selected for
digest verification is decided by the injected expression rather than
by the reference.
Problem types
-------------
- CWE-643 Improper Neutralization of Data within XPath Expressions
('XPath Injection')
- CWE-1287 Improper Validation of Specified Type of Input
Solutions
---------
Upgrade to version 0.71
References
----------
https://github.com/perl-net-saml2/perl-XML-Sig/commit/69ad2b421118fadd33d57f50b110b8d161e8fef5.patch
https://github.com/perl-net-saml2/perl-XML-Sig/commit/a85aad21aa767ac1c158bbfc19447683941ab376.patch
https://metacpan.org/release/TIMLEGGE/XML-Sig-0.71/changes