CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-9487

unknowncovered by 1 sourcefirst seen 2026-08-03
XML::Sig versions before 0.71 for Perl allow signature wrapping via duplicate ID. _get_signed_xml() in lib/XML/Sig.pm, called from verify(), resolves the SignedInfo Reference/@URI to a node with the XPath expression "//*[@ID='$id']" and returns the first node of the resulting node set. A document in which two elements share that ID value is accepted: the digest and signature are checked against whichever element comes first in document order, and the duplicate is not detected. Such a document verifies successfully while an application that resolves the same ID independently can read the second, attacker supplied element; in a SAML2 context this places the contents of an Assertion under attacker control.

⚡ Watch CVE-2026-9487

Get an email if CVE-2026-9487 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Advisory coverage (1)

External references

NVD record for CVE-2026-9487

CVE.org record

Embed the live status

CVE-2026-9487 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-9487 status](https://www.csirts.com/badge/CVE-2026-9487)](https://www.csirts.com/cve/CVE-2026-9487)