HarborGuard / CVE
Back to search
HIGHCVE-2026-32935Published Modified CNA GitHub_M

CVE-2026-32935: phpseclib's AES-CBC unpadding susceptible to padding oracle timing attack

phpseclib is a PHP secure communications library. Projects using versions 0.1.1 through 1.0.26, 2.0.0 through 2.0.51, and 3.0.0 through 3.0.49 are vulnerable to a to padding oracle timing attack when using AES in CBC mode. This issue has been fixed in versions 1.0.27, 2.0.52 and 3.0.50.

Metrics

CVSS v4.0
8.2
Severity
HIGH
Fixed in
Affected Products
1
Affected packages
  • phpseclib / phpseclib
    >= 3.0.0, < 3.0.50 · >= 2.0.0, < 2.0.52 · >= 0.1.1, < 1.0.27
CVSS Vector
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVE-2026-32935: phpseclib's AES-CBC unpadding susceptible to padding oracle timing attack | HarborGuard CVE