{"id":"GHSA-c4cc-x928-vjw9","summary":"robrichards/xmlseclibs has an Libxml2 Canonicalization error which can bypass Digest/Signature validation","details":"### Summary\nAn authentication bypass vulnerability exists due to a flaw in the libxml2 canonicalization process, which is used by [xmlseclibs](https://github.com/robrichards/xmlseclibs) during document transformation. This weakness allows an attacker to generate a valid signature once and reuse it indefinitely. In practice, a signature created during a previous interaction - or through a misconfigured authentication flow - can be replayed to bypass authentication checks.\n\n### Details\nWhen libxml2’s canonicalization is invoked on an invalid XML input, it may return an empty string rather than a canonicalized node. [xmlseclibs](https://github.com/robrichards/xmlseclibs) then proceeds to compute the DigestValue over this empty string, treating it as if canonicalization succeeded.\n\nhttps://github.com/robrichards/xmlseclibs/blob/f4131320c6dcd460f1b0c67f16f8bf24ce4b5c3e/src/XMLSecurityDSig.php#L296\n\n### Impact\nDigest bypass: By crafting input that causes canonicalization to yield an empty string, the attacker can manipulate validation to pass incorrectly.\n\nSignature replay on empty canonical form: If an empty string has been signed once (e.g., in a prior interaction or via a misconfigured flow), that signature can potentially be replayed to bypass authentication.\n\n### Suggested remediation\nTreat canonicalization failures (exceptions or nil/empty outputs) as fatal and abort validation.\nAdd explicit checks: reject when canonicalize returns nil/empty or raise","aliases":["CVE-2025-66578"],"modified":"2025-12-09T19:52:24.819272Z","published":"2025-12-08T17:57:33Z","database_specific":{"cwe_ids":["CWE-248"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2025-12-08T17:57:33Z","nvd_published_at":"2025-12-09T16:18:21Z"},"references":[{"type":"WEB","url":"https://github.com/robrichards/xmlseclibs/security/advisories/GHSA-c4cc-x928-vjw9"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-66578"},{"type":"WEB","url":"https://github.com/robrichards/xmlseclibs/commit/69fd63080bc47a8d51bc101c30b7cb756862d1d6"},{"type":"PACKAGE","url":"https://github.com/robrichards/xmlseclibs"},{"type":"WEB","url":"https://github.com/robrichards/xmlseclibs/blob/f4131320c6dcd460f1b0c67f16f8bf24ce4b5c3e/src/XMLSecurityDSig.php#L296"}],"affected":[{"package":{"name":"robrichards/xmlseclibs","ecosystem":"Packagist","purl":"pkg:composer/robrichards/xmlseclibs"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.1.4"}]}],"versions":["1.3.2","1.3.3","1.3.4","1.4.0","1.4.1","1.4.2","1.4.3","2.0.0","2.0.1","2.1.0","2.1.1","3.0.0","3.0.1","3.0.2","3.0.3","3.0.4","3.1.0","3.1.1","3.1.2","3.1.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/12/GHSA-c4cc-x928-vjw9/GHSA-c4cc-x928-vjw9.json","last_known_affected_version_range":"\u003c= 3.1.3"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L"}]}