Vulnerabilities in TIMLEGGE

14 results
Vexday analysis

TIMLEGGE apresenta 8 vulnerabilidades catalogadas, com 5 classificadas como críticas e atividade recente significativa: 4 publicadas nos últimos 90 dias. Não há registros de exploração ativa em campo (KEV), reduzindo o risco imediato, mas a fraqueza dominante em overflow aritmético (CWE-190) sugere problemas estruturais no tratamento de dados que demandam atenção em curto prazo.

CVE-2020-36846CRITICALIO::Compress::Brotli versions prior to 0.007 for Perl have an integer overflow in the bundled Brotli C libraryEPSS 0.6%CVE-2026-30909CRITICALCrypt::NaCl::Sodium versions through 2.002 for Perl has potential integer overflowsEPSS 0.5%CVE-2026-8700HIGHCrypt::DSA versions before 1.20 for Perl generate seeds using randEPSS 0.4%CVE-2026-2588CRITICALCrypt::NaCl::Sodium versions through 2.001 for Perl has an integer overflow flaw on 32-bit systemsEPSS 0.3%CVE-2026-8704MEDIUMCrypt::DSA versions through 1.19 for Perl use 2-args open, allowing existing files to be modifiedEPSS 0.3%CVE-2026-14570HIGHCrypt::DSA versions before 1.22 for Perl draw the DSA signing nonce and private key from a biased random generator, leading to private-key recoveryEPSS 0.3%CVE-2026-12205CRITICALCrypt::DSA versions before 1.21 for Perl reused the nonce across signatures, leading to private-key recoveryEPSS 0.3%CVE-2026-9390CRITICALXML::Sig versions before 0.71 for Perl allow XPath injection in ID lookupEPSS 0.3%CVE-2026-18108CRITICALNet::SAML2 versions before 0.86 for Perl allow authentication bypass because _verify_encrypted_assertion accepts an EncryptedAssertion whose decrypted content carries no signatureEPSS 0.2%CVE-2026-18092HIGHNet::SAML2 versions before 0.86 for Perl allow SAML authentication bypass via XML signature wrapping because new_from_xml reads assertion identity with document-wide XPath instead of the signed subtreeEPSS 0.2%CVE-2026-18568HIGHXML::Sig versions from 0.29 before 0.72 for Perl allow signature verification bypass because verify returns true when every signature was skipped before any cryptographic checkEPSS 0.2%CVE-2026-18089HIGHNet::SAML2 versions before 0.86 for Perl allow SAML authentication bypass by verifying responses against the response-embedded certificate in verify_xml when no trust anchor is configuredEPSS 0.2%CVE-2026-9487CRITICALXML::Sig versions before 0.71 for Perl allow signature wrapping via duplicate IDEPSS 0.2%CVE-2025-40934CRITICALXML-Sig prior to 0.68 for Perl improperly validates XML without signaturesEPSS 0.2%