🛡️ CVE-2026-18568 — \

🟠 CVSS 7.5 — High ✅ No Known Exploit CWE-347 NVD
7.5
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

XML::Sig versions from 0.29 before 0.72 for Perl allow signature verification bypass because verify returns true when every signature was skipped before any cryptographic check.

verify in lib/XML/Sig.pm counts the //dsig:Signature elements into $numsigs and iterates over them, but two paths reach next before any digest or key check runs: a SignedInfo/Reference/@URI that resolves to no element while $numsigs is greater than 1, and, when id_attr is set, a reference that does not match the requested ID. The loop records nothing about what it checked, so when every signature takes one of those paths control reaches the unconditional return 1 that ends verify. Two Signature elements whose Reference URI names an ID that no element carries is enough, as is one such element combined with id_attr.

Any caller that passes untrusted XML to verify can receive a true return for a document in which no digest and no signature value was checked; a cert or cert_text trust anchor does not change this, because no key check runs. Versions up to 0.28 use an XML::XPath based verify that has no such skip and are not affected.

How this vulnerability can be exploited

This issue can be reached over the network, attack complexity is low, an attacker needs no privileges on the target. No user interaction is required. The scope is unchanged, so the impact stays within the vulnerable component. Rated impact: confidentiality none, integrity high, availability none.

Weakness class

CVE-2026-18568 is classified as CWE-347: Improper Verification of Cryptographic Signature. A signature is not checked correctly, so forged or modified content is accepted as genuine.

Affected software

CVE-2026-18568 is recorded against 1 package.

  • \ (from 0.29 up to 0.72)

Timeline and source

Published on 3 August 2026 and last revised on 5 August 2026. No public exploit is currently recorded for this entry. A vendor advisory or fix has been published. Record sourced from NVD.

References

github.com
metacpan.org
www.cve.org

Details

Severity HIGH
CVSS Score 7.5
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CWE CWE-347
Public Exploit ✅ No
Source NVD
Published 2026-08-03
Updated 2026-08-11
Modified 2026-08-05

Affected Packages

Software From version Fixed in
\ 0.29 0.72

Site Security Check

Is \ part of your stack?

CVE-2026-18568 is rated CVSS 7.5 High. BotEraser scans your installation against known CVE records and tells you whether this vulnerability applies to the versions you actually run.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

Browse related advisories

All advisoriesCVECVE 2026