Skip to content

Releases: robrichards/xmlseclibs

4.0.0

Choose a tag to compare

@robrichards robrichards released this 08 Aug 11:00

xmlseclibs 4.0.0

PHP 8.0+ and phpseclib/phpseclib ~3.0 required; OpenSSL is optional.

Highlights

  • Crypto moved to phpseclib (symmetric, RSA, RSA-OAEP, X.509); RSA-PSS (RSA_SHA256_MGF1) supported
  • Safe-by-default verifyDocument() — pinned key, algorithm allowlists, validated node set
  • enableLegacyMode() for temporary pre-4.0 interop while migrating peers
  • Compact templates via stripWhitespace; omit_uri for references without a URI; extensibility via protected members (#152)

Security (breaking defaults)

  • DOCTYPE rejected on signature verify (entity-ref / Id bypass; same class of issue as CVE-2025-23369); also rejected in decrypted XML
  • XPath Filtering Transforms rejected on verify by default (pre-auth DoS); capped when enabled
  • RSA-1.5 key transport denied on decrypt by default; uniform decrypt errors (no padding oracle)
  • verify() always binds SignatureMethod to the supplied key; HMAC cannot be loaded from certs/PEM
  • References fail closed (unknown transforms, external/duplicate-Id URIs, unknown C14N)
  • SSRF hardening on add509Cert() URL fetch; EncryptedKey/RetrievalMethod depth caps; hash_equals for digests/HMAC

Other

  • Configurable transforms element; setSignatureId(); clearer throws when signature context is missing
  • Interop: whitespace-stripped signature/EncryptedData templates for C# SignedXml / Python signxml-style peers
  • PHP 8 / static-analysis hardening; PHP 8.5 deprecation fix in makeAsnSegment()

Migration

Prefer verifyDocument() with a pinned key. Use enableLegacyMode() only while updating peers — it restores DOCTYPE-on-verify, XPath transforms, and RSA-1.5; it does not undo algorithm/key binding, uniform decrypt errors, or decrypted-XML DOCTYPE rejection. Prefer RSA-OAEP and AES-GCM for new deployments.

Full detail: CHANGELOG.txt (4.0.0) and the “Breaking changes (3.1 → 4.0)” section in README.md.

Full Changelog: 3.1.5...4.0.0

3.1.5

Choose a tag to compare

@robrichards robrichards released this 13 Mar 10:35
03062be

Validate AES-GCM Authentication Tag

3.1.4

Choose a tag to compare

@robrichards robrichards released this 08 Dec 12:01
bc87389

fix canonicalization error

3.1.3

Choose a tag to compare

@robrichards robrichards released this 20 Nov 21:16

Removes BC breaking change

3.1.2

Choose a tag to compare

@robrichards robrichards released this 20 Nov 13:17

Add tab to list of whitespace values to remove from cert
loadKey should check return value for openssl_get_privatekey
Switch to GitHub actions
Support OAEP (from unreleased 3.1.1)

3.1.0

Choose a tag to compare

@robrichards robrichards released this 22 Apr 17:22

Add support for AES-GCM encryption
Minor improvements and bug fixes

3.0.4

Choose a tag to compare

@robrichards robrichards released this 06 Nov 12:06

Security Release for CVE-2019-3465

2.1.1

Choose a tag to compare

@robrichards robrichards released this 06 Nov 12:05

Security release

3.0.3

Choose a tag to compare

@robrichards robrichards released this 15 Nov 13:41

Add PHP 7.3 support

2.1.0

Choose a tag to compare

@robrichards robrichards released this 15 Nov 13:42

Backports changes from 3.0 branch.
This will be the last supported release from 2.x branch