Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-29774

34
FAUCET Score

CVE-2025-29774 is a critical vulnerability in the xml-crypto Node.js library (versions prior to 6.0.1, 3.2.1, and 2.1.6) that allows attackers to bypass authentication or authorization by modifying signed XML documents without invalidating the signature. This flaw, rated 9.3 Critical, enables privilege escalation or user impersonation by altering critical identity attributes. While no active exploitation, public exploit code, or significant community discussion has been observed, the high severity and potential for significant impact necessitate immediate patching.

Impacted Technologies

VendorProductVersion(s)CPE
Node-SamlXml-Crypto
< 2.1.6, >= 3.0.0, < 3.2.1, >= 4.0.0, < 6.0.1CNA affected

CVSS Data

CVSS version used by this source: 4.0

9.3CRITICAL

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
HIGH
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
9.05%
Probability of exploitation in next 30 days
EPSS Percentile
94.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0905 is in the 90th percentile among its peer group of 36,897 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (6)

npmpatch availablevia ghsa
Product: xml-cryptoFixed in: 6.0.1
npmpatch availablevia ghsa
Product: xml-cryptoFixed in: 3.2.1
npmpatch availablevia ghsa
Product: xml-cryptoFixed in: 2.1.6
redhatpatch availablevia redhat_api
Product: Red Hat Developer Hub 1.5Fixed in: rhdh/rhdh-hub-rhel9:sha256:56bfbb2328f42e91d0462e142f3434e5d771737defbc07d8a21dbdf50e468665
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Developer Hub (RHDH) 1.4Fixed in: rhdh/rhdh-hub-rhel9:sha256:577bd1595325229ba368ad2ece71faf31aec93c088e76c4bba507bf67e41753a
View patch
redhatend of lifevia redhat_api
Product: OpenShift ServerlessFixed in: openshift-serverless-1/kn-backstage-plugins-eventmesh-rhel8

Vendor Advisories (2)

npmGHSA-9p8x-f768-wp2gcritical

xml-crypto Vulnerable to XML Signature Verification Bypass via Multiple SignedInfo References

Mar 14, 2025
redhatCVE-2025-29774Important

xml-crypto: xml-crypto Vulnerable to XML Signature Verification Bypass via Multiple SignedInfo References

Mar 14, 2025

References

workos.com / blog/samlstorm
github.com / node-saml/xml-crypto/commit/28f92218ecbb8dcbd238afa4efbbd50302aa9aed
github.com / node-saml/xml-crypto/commit/886dc63a8b4bb5ae1db9f41c7854b171eb83aa98
github.com / node-saml/xml-crypto/commit/8ac6118ee7978b46aa56b82cbcaa5fca58c93a07
github.com / node-saml/xml-crypto/releases/tag/v2.1.6
github.com / node-saml/xml-crypto/releases/tag/v3.2.1
github.com / node-saml/xml-crypto/releases/tag/v6.0.1
github.com / node-saml/xml-crypto/security/advisories/GHSA-9p8x-f768-wp2g