CVE-2024-32962

CRITICAL

xml-crypto is an xml digital signature and encryption library for Node.js. In affected versions the default configuration does not check authorization of the signer, it only checks the validity of ...

Affects 0 products across 4 vendors.

BCS8.39
CVSS 3.110.0
EPSS0.8%
Percentile54th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, can impact systems beyond the vulnerable component, full confidentiality impact, full integrity impact, no availability impact.
CWE Weakness Definitions
CWE-347: CWE-347
Related Attack Patterns (CAPEC)
CAPEC-463 Padding Oracle Crypto Attack
via CWE-347
CAPEC-475 Signature Spoofing by Improper Validation
via CWE-347

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

CVE-2024-32962 affects the xml-crypto library for Node.js, where the default configuration does not verify the signer's authorization, allowing malicious actors to re-sign XML documents without proper validation.

BSID: BS-2024-GLOBAL-049876-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2024-32962?
CVE-2024-32962 affects the xml-crypto library for Node.js, where the default configuration does not verify the signer's authorization, allowing malicious actors to re-sign XML documents without proper validation.
What is the CVSS score for CVE-2024-32962?
CVE-2024-32962 has CVSS 10.0 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N. EPSS: 0.8%.
Is CVE-2024-32962 actively exploited?
No confirmed active exploitation of CVE-2024-32962 as of 2026-05-30.
How do I remediate CVE-2024-32962?
Priority: IMMEDIATE.
What systems are affected by CVE-2024-32962?
CVE-2024-32962 affects: Crypto, Digital, Element, Place.
Vulnerability Details
CVE IDCVE-2024-32962
BSIDBS-2024-GLOBAL-049876-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Published2024-05-02
Last Modified2026-04-15
ICS Relevance0%
Weakness (CWE)
SourceNVD
Official Description

xml-crypto is an xml digital signature and encryption library for Node.js. In affected versions the default configuration does not check authorization of the signer, it only checks the validity of the signature per section 3.2.2 of the w3 xmldsig-core-20080610 spec. As such, without additional validation steps, the default configuration allows a malicious actor to re-sign an XML document, place the certificate in a `<KeyInfo />` element, and pass `xml-crypto` default validation checks. As a result `xml-crypto` trusts by default any certificate provided via digitally signed XML document's `<KeyInfo />`. `xml-crypto` prefers to use any certificate provided via digitally signed XML document's `<KeyInfo />` even if library was configured to use specific certificate (`publicCert`) for signature verification purposes. An attacker can spoof signature verification by modifying XML document and replacing existing signature with signature generated with malicious private key (created by attacker) and by attaching that private key's certificate to `<KeyInfo />` element. This vulnerability is combination of changes introduced to `4.0.0` on pull request 301 / commit `c2b83f98` and has been addressed in version 6.0.0 with pull request 445 / commit `21201723d`. Users are advised to upgrade. Users unable to upgrade may either check the certificate extracted via `getCertFromKeyInfo` against trusted certificates before accepting the results of the validation or set `xml-crypto's getCertFromKeyInfo` to `() => undefined` forcing `xml-crypto` to use an explicitly configured `publicCert` or `privateKey` for signature verification.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

A malicious actor can exploit this vulnerability by re-signing XML documents with unauthorized keys, potentially leading to the acceptance of tampered data as legitimate.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductFixed Version
Crypto &mdash;
Digital &mdash;
Element &mdash;
Place &mdash;
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 826 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hash39490b3802860dfac61771be7db27ad80cfa4c0b14b825aa5a8970aa2f527170c806a80d920880216fe5b9fd3319478f2157a5d80c9c05a0f0d6187db0264816
Related CVEs affecting Crypto
CVE-2024-28285 9.8 A Fault Injection vulnerability in the SymmetricDecrypt function in cryptopp/... CVE-2026-43493 9.8 In the Linux kernel, the following vulnerability has been resolved: crypto: ... CVE-2025-68726 9.8 In the Linux kernel, the following vulnerability has been resolved: crypto: ... CVE-2024-31695 9.8 A misconfiguration in the fingerprint authentication mechanism of Binance: BT... CVE-2025-48141 9.3 Improper Neutralization of Special Elements used in an SQL Command ('SQL Inje...
View all Crypto CVEs →

Critical Severity - Know Your Exposure

A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →