{"id":"CVE-2026-32935","aliases":["GHSA-94g3-g5v7-q4jg"],"url":"https://o3.security/vulnerability/CVE-2026-32935","summary":"phpseclib's AES-CBC unpadding susceptible to padding oracle timing attack","details":"phpseclib is a PHP secure communications library. Projects using versions 0.1.1 through 1.0.26, 2.0.0 through 2.0.51, and 3.0.0 through 3.0.49 are vulnerable to a to padding oracle timing attack when using AES in CBC mode. This issue has been fixed in versions 1.0.27, 2.0.52 and 3.0.50.","published":"2026-03-20T02:48:59.778Z","modified":"2026-08-07T11:48:53.467164135Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"phpseclib/phpseclib","fixedVersion":"3.0.50"},{"ecosystem":"Packagist","name":"phpseclib/phpseclib","fixedVersion":"2.0.52"},{"ecosystem":"Packagist","name":"phpseclib/phpseclib","fixedVersion":"1.0.27"}],"fix":{"url":"https://github.com/phpseclib/phpseclib/commit/ccc21aef71eb170e9bf819b167e67d1fd9e6e788","label":"phpseclib/phpseclib@ccc21ae"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/32xxx/CVE-2026-32935.json"},{"type":"ADVISORY","url":"https://github.com/phpseclib/phpseclib/security/advisories/GHSA-94g3-g5v7-q4jg"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-32935"},{"type":"FIX","url":"https://github.com/phpseclib/phpseclib/commit/ccc21aef71eb170e9bf819b167e67d1fd9e6e788"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T11:48:53.467164135Z"}}