A vulnerability was found in XML::Sig up to 0.70. It has been rated as problematic. Affected by this issue is the function
verify/_get_signed_xml of the file lib/XML/Sig.pm of the component XPath Builder. The manipulation of the argument URI leads to injection.
This vulnerability is referenced as CVE-2026-9390. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is advised.