XPath Injection in XMLSecLibs - #VU145059
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper neutralization of data within XPath expressions in processTransforms() when validating references that include REC-xpath-19991116 Transform elements. A remote attacker can supply a crafted XPath expression to cause a denial of service.
Only instances that enable XMLSecurityDSig::$allowXPathTransforms on the verification path are vulnerable.