Skip to content

Commit f7da15c

Browse files
committed
v4.0.4
1 parent 97e1f48 commit f7da15c

File tree

1 file changed

+12
-0
lines changed

1 file changed

+12
-0
lines changed

Changes.rst

Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,15 @@
1+
Changes for v4.0.4 (2025-06-01)
2+
===============================
3+
4+
This release contains security fixes for two security advisories:
5+
6+
- Signature verification with HMAC is vulnerable to an algorithm
7+
confusion attack
8+
(https://github.com/XML-Security/signxml/security/advisories/GHSA-6vx8-pcwv-xhf4)
9+
10+
- Signature verification with HMAC is vulnerable to a timing attack
11+
(https://github.com/XML-Security/signxml/security/advisories/GHSA-gmhf-gg8w-jw42)
12+
113
Changes for v4.0.3 (2024-11-23)
214
===============================
315

0 commit comments

Comments
 (0)