Advisories for Composer/Robrichards/Xmlseclibs package

2025

robrichards/xmlseclibs has an Libxml2 Canonicalization error which can bypass Digest/Signature validation

An authentication bypass vulnerability exists due to a flaw in the libxml2 canonicalization process, which is used by xmlseclibs during document transformation. This weakness allows an attacker to generate a valid signature once and reuse it indefinitely. In practice, a signature created during a previous interaction - or through a misconfigured authentication flow - can be replayed to bypass authentication checks.

2024
2019
2018