timlegge
OSS Librariesunknown
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting timlegge.
- CVE-2026-18568XML::Sig versions from 0.29 before 0.72 for Perl allow signature verification bypass because verify returns true when every signature was skipped before any cryptographic check7.5
- CVE-2026-18092Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass via XML signature wrapping because new_from_xml reads assertion identity with document-wide XPath instead of the signed subtree8.1
- CVE-2026-9487XML::Sig versions before 0.71 for Perl allow signature wrapping via duplicate ID9.1
- CVE-2026-9390XML::Sig versions before 0.71 for Perl allow XPath injection in ID lookup9.1
- CVE-2026-18108Net::SAML2 versions before 0.86 for Perl allow authentication bypass because _verify_encrypted_assertion accepts an EncryptedAssertion whose decrypted content carries no signature9.8
- CVE-2026-18089Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass by verifying responses against the response-embedded certificate in verify_xml when no trust anchor is configured7.5
- CVE-2026-14570Crypt::DSA versions before 1.22 for Perl draw the DSA signing nonce and private key from a biased random generator, leading to private-key recovery7.5
- CVE-2026-12205Crypt::DSA versions before 1.21 for Perl reused the nonce across signatures, leading to private-key recovery9.1
- CVE-2026-8704Crypt::DSA versions through 1.19 for Perl use 2-args open, allowing existing files to be modified6.5
- CVE-2026-8700Crypt::DSA versions before 1.20 for Perl generate seeds using rand7.3
- CVE-2026-30909Crypt::NaCl::Sodium versions through 2.002 for Perl has potential integer overflows9.8
- CVE-2026-2588Crypt::NaCl::Sodium versions through 2.001 for Perl has an integer overflow flaw on 32-bit systems9.1
- CVE-2025-40934XML-Sig prior to 0.68 for Perl improperly validates XML without signatures9.3
- CVE-2020-36846IO::Compress::Brotli versions prior to 0.007 for Perl have an integer overflow in the bundled Brotli C library9.8
- CVE-2025-1828Perl's Crypt::Random module after 1.05 and before 1.56 may use rand() function for cryptographic functions8.8