Information Exposure Through Timing Discrepancy in XMLSecLibs - #VU145061
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to recover valid message authentication codes.
The vulnerability exists due to an observable timing discrepancy in XMLSecurityKey::verifySignature() when verifying HMAC-SHA1 signatures. A remote attacker can measure response timing differences to recover valid message authentication codes.
Exploitation may be possible byte-by-byte under favorable network conditions.