Uncaught Exception Affecting robrichards/xmlseclibs package, versions <3.1.4


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.05% (15th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Uncaught Exception vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PHP-ROBRICHARDSXMLSECLIBS-14236429
  • published12 Dec 2025
  • disclosed9 Dec 2025
  • creditd0ge

Introduced: 9 Dec 2025

NewCVE-2025-66578  (opens in a new tab)
CWE-248  (opens in a new tab)

How to fix?

Upgrade robrichards/xmlseclibs to version 3.1.4 or higher.

Overview

robrichards/xmlseclibs is a PHP library for XML Security.

Affected versions of this package are vulnerable to Uncaught Exception in the form of improper handling of canonicalization failures. An attacker can bypass signature or digest validation by submitting specially crafted invalid XML input that causes the process to return an empty string, leading to incorrect digest computation and validation.

CVSS Base Scores

version 4.0
version 3.1