# CVE-2025-48995

## Summary

- **CVE ID:** CVE-2025-48995
- **Severity:** MEDIUM
- **CVSS Score:** 6.9 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N)
- **CWE:** CWE-208
- **Published:** Jun 2, 2025
- **Last Modified:** Mar 13, 2026

## Description

SignXML is an implementation of the W3C XML Signature standard in Python. When verifying signatures with X509 certificate validation turned off and HMAC shared secret set (`signxml.XMLVerifier.verify(require_x509=False, hmac_key=...`), versions of SignXML prior to 4.0.4 are vulnerable to a potential timing attack. The verifier may leak information about the correct HMAC when comparing it with the user supplied hash, allowing users to reconstruct the correct HMAC for any data.

## Affected Products

- XML-Security — signxml (< 4.0.4)

## References

- [CNA](https://github.com/XML-Security/signxml/security/advisories/GHSA-gmhf-gg8w-jw42)
- [CNA](https://github.com/XML-Security/signxml/commit/1b501faaacf34cf978a52dbc6915ec11e27611cd)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.23%
- **EPSS Percentile:** 13.7

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._