Changes for version 0.71 - 2026-07-30

  • Notable Changes
    • Security Fixes CVE-2026-9487 and CVE-2026-9390 CVE-2026-9390 enforces a subset of the characters allowed in an ID CVE-2026-9487 rejects signature checking if the ID references multiple nodes
  • Change Log
    • 7ac376f Update the release to use sigstore for signing
    • 7385a2a Update contact email address (replace cpan.org)
    • c0dd9f5 Update the build items dependencies and version
    • e59c13b Document the allowed characters in an ID
    • 4976bde Reject Duplicate IDs in XML document (CVE-2026-9487)
    • ef7a52b Fix some invalid characters in the array
    • f92a5b5 UTF8 in XML needs to be encoded to avoid Wide character errors
    • 9f54cb8 Add a mailmap file
    • a85aad2 improve the regex
    • 69ad2b4 Enforce the ID format as per the specification Reject any XML ids with invalid characters (CVE-2026-9390)
    • abd726a use instead of ->{parser} when called multiple times
    • 92970ff _load_key should not return anything
    • 1532383 v0.70

Documentation

Modules

XML::Sig - A toolkit to help sign and verify XML Digital Signatures