---
id: CVE-2025-48995
aliases:
  - GHSA-gmhf-gg8w-jw42
  - PYSEC-2026-1922
title: SignXML's signature verification with HMAC is vulnerable to a timing attack
summary: SignXML's signature verification with HMAC is vulnerable to a timing attack
severity: medium
vendor: signxml
product: signxml
ecosystem: pip
affected:
  - signxml < 4.0.4
patched:
  - signxml 4.0.4
published: '2025-06-05'
updated: '2026-07-07'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-gmhf-gg8w-jw42'
references:
  - url: >-
      https://github.com/XML-Security/signxml/security/advisories/GHSA-gmhf-gg8w-jw42
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2025-48995'
  - url: >-
      https://github.com/XML-Security/signxml/commit/1b501faaacf34cf978a52dbc6915ec11e27611cd
  - url: 'https://github.com/XML-Security/signxml'
tags:
  - osv
  - pip
epss: 0.00229
epssPercentile: 0.12209
ingestedAt: '2026-07-08T18:25:49.738Z'
---

## Overview

When verifying signatures with X509 certificate validation turned off and HMAC shared secret set (`signxml.XMLVerifier.verify(require_x509=False, hmac_key=...`), prior versions of SignXML are vulnerable to a potential timing attack. The verifier may leak information about the correct HMAC when comparing it with the user supplied hash, allowing users to reconstruct the correct HMAC for any data.

## Affected packages

- `signxml < 4.0.4`

## Remediation

Upgrade to a patched release:

- `signxml 4.0.4`
