Report: CVE-2026-32935 - phpseclib's AES-CBC unpadding susceptible to padding oracle timing attack

Report: CVE-2026-32935 - phpseclib's AES-CBC unpadding susceptible to padding oracle timing attack

CVE ID :CVE-2026-32935 Published : March 20, 2026, 3:16 a.m. | 36 minutes ago Description :phpseclib is a PHP secure communications library. Projects using versions 1.0.26 and below, 2.0.0 through 2.0.51, and 3.0.0 through 3.0.49 are vulnerable to a to padding oracle timing attack when using AES in CBC mode. This issue has been fixed in versions 1.0.27, 2.0.52 and 3.0.50. Severity: 8.2 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
HIGH
Published
March 20, 2026
Affected Product: PHP