{"id":"CVE-2025-48995","aliases":["GHSA-gmhf-gg8w-jw42","PYSEC-2026-1922"],"title":"SignXML's signature verification with HMAC is vulnerable to a timing attack","summary":"SignXML's signature verification with HMAC is vulnerable to a timing attack","severity":"medium","vendor":"signxml","product":"signxml","ecosystem":"pip","affected":["signxml < 4.0.4"],"patched":["signxml 4.0.4"],"published":"2025-06-05","updated":"2026-07-07","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-gmhf-gg8w-jw42","references":[{"url":"https://github.com/XML-Security/signxml/security/advisories/GHSA-gmhf-gg8w-jw42"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-48995"},{"url":"https://github.com/XML-Security/signxml/commit/1b501faaacf34cf978a52dbc6915ec11e27611cd"},{"url":"https://github.com/XML-Security/signxml"}],"tags":["osv","pip"],"epss":0.00229,"epssPercentile":0.13982,"ingestedAt":"2026-07-08T18:25:49.738Z","slug":"CVE-2025-48995","body":"## Overview\n\nWhen verifying signatures with X509 certificate validation turned off and HMAC shared secret set (`signxml.XMLVerifier.verify(require_x509=False, hmac_key=...`), prior versions of SignXML are vulnerable to a potential timing attack. The verifier may leak information about the correct HMAC when comparing it with the user supplied hash, allowing users to reconstruct the correct HMAC for any data.\n\n## Affected packages\n\n- `signxml < 4.0.4`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `signxml 4.0.4`","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":27.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}