CyberIntel ⬡ News
★ Saved ◆ Cyber Reads
← Back ⬡ Vulnerabilities & CVEs Mar 26, 2026

CVE-2026-33487 | russellhaering goxmldsig up to 1.5.x XML Digital Signature validateSignature signature verification

VulDB Archived Mar 26, 2026 ✓ Full text saved

A vulnerability, which was classified as problematic , was found in russellhaering goxmldsig up to 1.5.x . Affected by this issue is the function validateSignature of the component XML Digital Signature Handler . Such manipulation leads to improper verification of cryptographic signature. This vulnerability is traded as CVE-2026-33487 . The attack may be launched remotely. There is no exploit available. You should upgrade the affected component.

Full text archived locally
✦ AI Summary · Claude Sonnet


    VDB-353685 · CVE-2026-33487 · GCVE-0-2026-33487 RUSSELLHAERING GOXMLDSIG UP TO 1.5.X XML DIGITAL SIGNATURE VALIDATESIGNATURE SIGNATURE VERIFICATION HISTORYDIFFRELATEJSONXMLCTI CVSS Meta Temp Score Current Exploit Price (≈) CTI Interest Score 5.5 $0-$5k 1.63+ Summaryinfo A vulnerability has been found in russellhaering goxmldsig up to 1.5.x and classified as problematic. This affects the function validateSignature of the component XML Digital Signature Handler. Performing a manipulation results in signature verification. This vulnerability is known as CVE-2026-33487. Remote exploitation of the attack is possible. No exploit is available. The affected component should be upgraded. Detailsinfo A vulnerability, which was classified as problematic, was found in russellhaering goxmldsig up to 1.5.x. This affects the function validateSignature of the component XML Digital Signature Handler. The manipulation with an unknown input leads to a signature verification vulnerability. CWE is classifying the issue as CWE-347. The product does not verify, or incorrectly verifies, the cryptographic signature for data. This is going to have an impact on integrity. The summary by CVE is: goxmlsig provides XML Digital Signatures implemented in Go. Prior to version 1.6.0, the `validateSignature` function in `validate.go` goes through the references in the `SignedInfo` block to find one that matches the signed element's ID. In Go versions before 1.22, or when `go.mod` uses an older version, there is a loop variable capture issue. The code takes the address of the loop variable `_ref` instead of its value. As a result, if more than one reference matches the ID or if the loop logic is incorrect, the `ref` pointer will always end up pointing to the last element in the `SignedInfo.References` slice after the loop. goxmlsig version 1.6.0 contains a patch. The advisory is shared at github.com. This vulnerability is uniquely identified as CVE-2026-33487 since 03/20/2026. The exploitability is told to be difficult. It is possible to initiate the attack remotely. No form of authentication is needed for exploitation. Technical details are known, but no exploit is available. Upgrading to version 1.6.0 eliminates this vulnerability. Productinfo Vendor russellhaering Name goxmldsig Version 1.0 1.1 1.2 1.3 1.4 1.5 Website Product: https://github.com/russellhaering/goxmldsig/ CPE 2.3info 🔒 🔒 🔒 CPE 2.2info 🔒 🔒 🔒 CVSSv4info VulDB Vector: 🔒 VulDB Reliability: 🔍 CVSSv3info VulDB Meta Base Score: 5.6 VulDB Meta Temp Score: 5.5 VulDB Base Score: 3.7 VulDB Temp Score: 3.6 VulDB Vector: 🔒 VulDB Reliability: 🔍 CNA Base Score: 7.5 CNA Vector (GitHub_M): 🔒 CVSSv2info Vector Complexity Authentication Confidentiality Integrity Availability Unlock Unlock Unlock Unlock Unlock Unlock Unlock Unlock Unlock Unlock Unlock Unlock Unlock Unlock Unlock Unlock Unlock Unlock VulDB Base Score: 🔒 VulDB Temp Score: 🔒 VulDB Reliability: 🔍 Exploitinginfo Class: Signature verification CWE: CWE-347 / CWE-345 CAPEC: 🔒 ATT&CK: 🔒 Physical: No Local: No Remote: Yes Availability: 🔒 Status: Not defined Price Prediction: 🔍 Current Price Estimation: 🔒 0-Day Unlock Unlock Unlock Unlock Today Unlock Unlock Unlock Unlock Threat Intelligenceinfo Interest: 🔍 Active Actors: 🔍 Active APT Groups: 🔍 Countermeasuresinfo Recommended: Upgrade Status: 🔍 0-Day Time: 🔒 Upgrade: goxmldsig 1.6.0 Timelineinfo 03/20/2026 CVE reserved 03/26/2026 +6 days Advisory disclosed 03/26/2026 +0 days VulDB entry created 03/26/2026 +0 days VulDB entry last update Sourcesinfo Product: github.com Advisory: github.com Status: Confirmed CVE: CVE-2026-33487 (🔒) GCVE (CVE): GCVE-0-2026-33487 GCVE (VulDB): GCVE-100-353685 Entryinfo Created: 03/26/2026 19:02 Changes: 03/26/2026 19:02 (64) Complete: 🔍 Cache ID: 99:E13:101 Discussion No comments yet. Languages: en. Please log in to comment. ◂ PreviousOverviewNext ▸
    💬 Team Notes
    Article Info
    Source
    VulDB
    Category
    ⬡ Vulnerabilities & CVEs
    Published
    Mar 26, 2026
    Archived
    Mar 26, 2026
    Full Text
    ✓ Saved locally
    Open Original ↗