Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4518-1 | phpseclib security update |
Debian DSA |
DSA-6185-1 | phpseclib security update |
Debian DSA |
DSA-6186-1 | php-phpseclib security update |
Debian DSA |
DSA-6187-1 | php-phpseclib3 security update |
Github GHSA |
GHSA-94g3-g5v7-q4jg | phpseclib's AES-CBC unpadding susceptible to padding oracle timing attack |
Fri, 08 May 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | phpseclib is a PHP secure communications library. Projects using versions 1.0.26 and below, 2.0.0 through 2.0.51, and 3.0.0 through 3.0.49 are vulnerable to a to padding oracle timing attack when using AES in CBC mode. This issue has been fixed in versions 1.0.27, 2.0.52 and 3.0.50. | phpseclib is a PHP secure communications library. Projects using versions 0.1.1 through 1.0.26, 2.0.0 through 2.0.51, and 3.0.0 through 3.0.49 are vulnerable to a to padding oracle timing attack when using AES in CBC mode. This issue has been fixed in versions 1.0.27, 2.0.52 and 3.0.50. |
Mon, 23 Mar 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:phpseclib:phpseclib:*:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Fri, 20 Mar 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 20 Mar 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Phpseclib
Phpseclib phpseclib |
|
| Vendors & Products |
Phpseclib
Phpseclib phpseclib |
Fri, 20 Mar 2026 03:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | phpseclib is a PHP secure communications library. Projects using versions 1.0.26 and below, 2.0.0 through 2.0.51, and 3.0.0 through 3.0.49 are vulnerable to a to padding oracle timing attack when using AES in CBC mode. This issue has been fixed in versions 1.0.27, 2.0.52 and 3.0.50. | |
| Title | phpseclib's AES-CBC unpadding susceptible to padding oracle timing attack | |
| Weaknesses | CWE-208 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-08T15:19:11.716Z
Reserved: 2026-03-17T00:05:53.282Z
Link: CVE-2026-32935
Updated: 2026-03-20T16:32:14.624Z
Status : Modified
Published: 2026-03-20T03:16:00.763
Modified: 2026-05-08T16:16:10.330
Link: CVE-2026-32935
No data.
OpenCVE Enrichment
Updated: 2026-05-08T19:15:14Z
Debian DLA
Debian DSA
Github GHSA