What is CVE-2026-9390?
CVE-2026-9390 affects XML::Sig library for Perl versions before 0.71, allowing XPath injection in ID lookup via "verify()" and "_get_signed_xml()" functions. Users should upgrade XML::Sig to version 0.71 or later.
Azərbaycanca: CVE-2026-9390, Perl-in XML::Sig kitabxanasının 0.71-dən əvvəlki versiyalarında aşkarlanmışdır. Bu zəiflik hücumçuya "verify()" və "_get_signed_xml()" funksiyalarında XPath ifadələrinə injection etməyə imkan yaradır. İstifadəçilər XML::Sig kitabxanasını 0.71 və ya daha yuxarı versiyaya yeniləməlidir.
FAQ2
Which versions of the XML::Sig library for Perl are affected by CVE-2026-9390?
This vulnerability affects versions of the XML::Sig library before 0.71. Therefore, users should upgrade to version 0.71 or later.
What does CVE-2026-9390 allow an attacker to do specifically within the XML::Sig library?
The vulnerability allows an attacker to inject XPath expressions via the "verify()" and "_get_signed_xml()" functions.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.