Upstream maintainer here. I tried to reproduce the reported failure in the test suite on latest lasso (2.9.0) by compiling xmlsec 1.3.7 locally with the same configuration flags as the experimental package on Debian but I cannot reproduce the problem.
This bug has been merged with 1106894, and marked as fixed upstream, with https://dev.entrouvert.org/issues/106375, so it's expected an upcoming newer release wouldn't have it.
I didn't upload a package with the backported patch as "[this bug is NOT targeted to the upcoming trixie release]".

