VendorsXMLSecLibs Projectxmlseclibsany version
Vulnerabilities

XMLSecLibs Project XMLSecLibs any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2019-3465
Rob Richards XmlSecLibs, all versions prior to v3.0.3, as used for example by SimpleSAMLphp, performed incorrect validation of cryptographic signatures in XML messages, allowing an authenticated attacker to impersonate others or elevate privileges by creating a crafted XML message.
Published 2019-11-07 · Modified
8.8EPSS 0.030
CVE-2026-32313
xmlseclibs is Missing AES-GCM Authentication Tag Validation on Encrypted Nodes Allows for Unauthorized Decryption
Published 2026-03-13 · Analyzed
8.2EPSS 0.002
CVE-2025-66578
robrichards/xmlseclibs has an Libxml2 Canonicalization error which can bypass Digest/Signature validation
Published 2025-12-09 · Analyzed
7.5EPSS 0.002