{"id":"CVE-2025-48994","aliases":["GHSA-6vx8-pcwv-xhf4","PYSEC-2026-1921"],"title":"SignXML's signature verification with HMAC is vulnerable to an algorithm confusion attack","summary":"SignXML's signature verification with HMAC is vulnerable to an algorithm confusion attack","severity":"medium","vendor":"signxml","product":"signxml","ecosystem":"pip","affected":["signxml < 4.0.4"],"patched":["signxml 4.0.4"],"published":"2025-06-05","updated":"2026-07-07","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-6vx8-pcwv-xhf4","references":[{"url":"https://github.com/XML-Security/signxml/security/advisories/GHSA-6vx8-pcwv-xhf4"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-48994"},{"url":"https://github.com/XML-Security/signxml/commit/e3c0c2b82a3329a65d917830657649c98b8c7600"},{"url":"https://github.com/XML-Security/signxml"}],"tags":["osv","pip"],"epss":0.00219,"epssPercentile":0.12635,"ingestedAt":"2026-07-08T18:25:46.538Z","slug":"CVE-2025-48994","body":"## Overview\n\nWhen verifying signatures with X509 certificate validation turned off and HMAC shared secret set (`signxml.XMLVerifier.verify(require_x509=False, hmac_key=...`), prior versions of SignXML are vulnerable to a potential algorithm confusion attack. Unless the user explicitly limits the expected signature algorithms using the `signxml.XMLVerifier.verify(expect_config=...)` setting, an attacker may supply a signature unexpectedly signed with a key other than the provided HMAC key, using a different (asymmetric key) signature algorithm.\n\nStarting with signxml 4.0.4, specifying `hmac_key` causes the set of accepted signature algorithms to be restricted to HMAC only, if not already restricted by the user.\n\n## Affected packages\n\n- `signxml < 4.0.4`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `signxml 4.0.4`","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":27.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}