
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-32313 is a cryptographic bypass vulnerability in the xmlseclibs PHP library, formally titled "Missing AES-GCM Authentication Tag Validation on Encrypted Nodes Allows for Unauthorized Decryption." It affects all versions of robrichards/xmlseclibs prior to 3.1.5 and was disclosed on March 13, 2026, with the patch released the same day. The flaw allows unauthenticated remote attackers to decrypt AES-GCM encrypted XML nodes, recover the internal GHASH key, and forge arbitrary ciphertexts. It carries a CVSS v3.1 base score of 8.2 (High) (Github Advisory, GHSA Security Advisory).
The root cause is classified as CWE-354 (Improper Validation of Integrity Check Value). In the decryptSymmetric() method of XMLSecurityKey.php, when decrypting data using aes-128-gcm, aes-192-gcm, or aes-256-gcm, the authentication tag ($authTag) is extracted via substr() but its length is never validated against the expected 16-byte (AUTHTAG_LENGTH) value. Because PHP's substr() with a negative offset on a short input string can return a string shorter than 16 bytes, an attacker can craft a payload where the authentication tag is as short as one byte, effectively bypassing GCM's integrity protection. With a legitimate ciphertext and the ability to submit crafted requests and observe HTTP 500 error responses (a format validation oracle), an attacker can brute-force the authentication tag byte-by-byte (256 attempts per byte), then use the recovered empty-ciphertext tag to compute the GHASH key offline — enabling decryption of arbitrary ciphertexts and forgery of new ones (GHSA Security Advisory, Patch Commit).
Successful exploitation allows an unauthenticated network attacker to decrypt XML nodes protected with AES-GCM encryption, recover the GCM GHASH key, and forge arbitrary ciphertexts without knowledge of the encryption key. In SAML deployments where symmetric keys are generated per-response and wrapped with the Service Provider's public key, the primary risk is decryption of secrets embedded in XML (e.g., SAML assertions). The risk is significantly elevated for systems using static symmetric AES-GCM keys, as the recovered GHASH key may have been leaked, enabling retrospective decryption of all previously encrypted data and active forgery of encrypted values (GHSA Security Advisory).
A detailed proof-of-concept exploit script (nonce_reuse_with_fmt_val_oracle.py, runnable with SageMath) is publicly available as part of the security advisory, implementing the full tag brute-force and GHASH key recovery attack against a live xmlseclibs server (GHSA Security Advisory). The vulnerability requires no authentication, no privileges, and no user interaction, making it trivially exploitable over the network. The EPSS score is approximately 0.052% (17th percentile), and there is no current evidence of in-the-wild exploitation or CISA KEV catalog listing. No specific threat actor attribution has been reported.
robrichards/xmlseclibs < 3.1.5 for XML decryption (e.g., a SAML Service Provider). Confirm the endpoint accepts XML with AES-GCM encrypted nodes and returns HTTP 500 on decryption/parsing failures.Steps 3–6 are automated by the exploit script nonce_reuse_with_fmt_val_oracle.py (run with sage -python nonce_reuse_with_fmt_val_oracle.py -s '<url-encoded-base64-samlresponse>') (GHSA Security Advisory).
openssl_decrypt failures or authentication tag errors prior to the patch being applied.Upgrade robrichards/xmlseclibs to version 3.1.5 or later, which adds an explicit length check (strlen($authTag) !== self::AUTHTAG_LENGTH) before passing the authentication tag to openssl_decrypt(), preventing short-tag bypass (Patch Commit, Release 3.1.5). If your application uses static symmetric AES-GCM keys, immediately rotate all such keys, as the GHASH key may have been recovered by an attacker. Review any encrypted XML data processed prior to patching for signs of unauthorized access. No configuration-based workaround is available; upgrading is the only remediation (GHSA Security Advisory).
The vulnerability was reported by a researcher identified as "Sideni" and disclosed via GitHub's security advisory process on March 13, 2026. Cisco's Duo Access Gateway release notes from June 2026 reference this CVE, indicating downstream product impact and patching activity (Cisco Duo Release Notes). The Hacker Wire noted the disclosure on Mastodon shortly after publication. Community reaction has been moderate, with security aggregators including VulDB and threat intelligence platforms tracking the issue.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."