CVE-2025-48995 | XML-Security signxml up to 4.0.3 timing discrepancy (GHSA-gmhf-gg8w-jw42 / Nessus ID 264351)
A vulnerability identified as problematic has been detected in XML-Security signxml up to 4.0.3. This affects an unknown part. Performing manipulation results in observable timing discrepancy.
This vulnerability is identified as CVE-2025-48995. The attack can be initiated remotely. There is not any exploit available.
You should upgrade the affected component.