CVE-2026-32313: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-32313 is a cryptographic bypass vulnerability in the xmlseclibs PHP library, formally titled "Missing AES-GCM Authentication Tag Validation on Encrypted Nodes Allows for Unauthorized Decryption." It affects all versions of robrichards/xmlseclibs prior to 3.1.5 and was disclosed on March 13, 2026, with the patch released the same day. The flaw allows unauthenticated remote attackers to decrypt AES-GCM encrypted XML nodes, recover the internal GHASH key, and forge arbitrary ciphertexts. It carries a CVSS v3.1 base score of 8.2 (High) (Github Advisory, GHSA Security Advisory).

Technical details

The root cause is classified as CWE-354 (Improper Validation of Integrity Check Value). In the decryptSymmetric() method of XMLSecurityKey.php, when decrypting data using aes-128-gcm, aes-192-gcm, or aes-256-gcm, the authentication tag ($authTag) is extracted via substr() but its length is never validated against the expected 16-byte (AUTHTAG_LENGTH) value. Because PHP's substr() with a negative offset on a short input string can return a string shorter than 16 bytes, an attacker can craft a payload where the authentication tag is as short as one byte, effectively bypassing GCM's integrity protection. With a legitimate ciphertext and the ability to submit crafted requests and observe HTTP 500 error responses (a format validation oracle), an attacker can brute-force the authentication tag byte-by-byte (256 attempts per byte), then use the recovered empty-ciphertext tag to compute the GHASH key offline — enabling decryption of arbitrary ciphertexts and forgery of new ones (GHSA Security Advisory, Patch Commit).

Impact

Successful exploitation allows an unauthenticated network attacker to decrypt XML nodes protected with AES-GCM encryption, recover the GCM GHASH key, and forge arbitrary ciphertexts without knowledge of the encryption key. In SAML deployments where symmetric keys are generated per-response and wrapped with the Service Provider's public key, the primary risk is decryption of secrets embedded in XML (e.g., SAML assertions). The risk is significantly elevated for systems using static symmetric AES-GCM keys, as the recovered GHASH key may have been leaked, enabling retrospective decryption of all previously encrypted data and active forgery of encrypted values (GHSA Security Advisory).

Exploitability

A detailed proof-of-concept exploit script (nonce_reuse_with_fmt_val_oracle.py, runnable with SageMath) is publicly available as part of the security advisory, implementing the full tag brute-force and GHASH key recovery attack against a live xmlseclibs server (GHSA Security Advisory). The vulnerability requires no authentication, no privileges, and no user interaction, making it trivially exploitable over the network. The EPSS score is approximately 0.052% (17th percentile), and there is no current evidence of in-the-wild exploitation or CISA KEV catalog listing. No specific threat actor attribution has been reported.

Exploitation steps

  1. Reconnaissance: Identify a target server running a PHP application that uses robrichards/xmlseclibs < 3.1.5 for XML decryption (e.g., a SAML Service Provider). Confirm the endpoint accepts XML with AES-GCM encrypted nodes and returns HTTP 500 on decryption/parsing failures.
  2. Obtain a legitimate ciphertext: Capture or generate a valid SAMLResponse (or other XML document) containing an AES-GCM encrypted node. Base64-decode the encrypted node content to extract the 12-byte nonce and the ciphertext.
  3. Brute-force the authentication tag byte-by-byte: For each of the 16 tag bytes, loop through all 256 possible byte values. Construct a payload consisting of the nonce concatenated with the current tag attempt (starting with 1 byte), Base64-encode it, and submit it to the target endpoint. An HTTP 500 response indicating a valid tag (rather than a tag rejection) reveals the correct byte. Repeat for each subsequent byte until the full 16-byte tag for an empty ciphertext is recovered.
  4. Recover the GHASH key: Using the brute-forced authentication tag for the empty ciphertext and the known nonce, compute the GCM GHASH key offline using the mathematical relationship described in the referenced OpenSSL blog post.
  5. Decrypt arbitrary ciphertexts: Use the recovered GHASH key to compute valid authentication tags for arbitrary ciphertexts offline. Submit modified encrypted nodes to the server and observe XML parsing error differences (HTTP 500 vs. success) to perform chosen-ciphertext decryption of embedded secrets.
  6. Forge ciphertexts (if static keys are used): With the GHASH key, compute authentication tags for attacker-controlled plaintext, enabling injection of forged encrypted values into XML documents processed by the server.

Steps 3–6 are automated by the exploit script nonce_reuse_with_fmt_val_oracle.py (run with sage -python nonce_reuse_with_fmt_val_oracle.py -s '<url-encoded-base64-samlresponse>') (GHSA Security Advisory).

Indicators of compromise

  • Network: High volume of HTTP POST requests to SAML or XML processing endpoints from a single source IP, particularly requests with unusually short or malformed Base64-encoded encrypted node content; repeated HTTP 500 responses from the XML processing endpoint in rapid succession (indicative of tag brute-forcing).
  • Logs: Web server access logs showing hundreds to thousands of requests to the same XML/SAML endpoint within a short time window, each with slightly varying request body content; PHP error logs showing repeated openssl_decrypt failures or authentication tag errors prior to the patch being applied.
  • Application Behavior: Unexpected decryption of XML nodes that should have failed integrity validation; XML parsing errors logged server-side following submission of crafted encrypted payloads.

Mitigation and workarounds

Upgrade robrichards/xmlseclibs to version 3.1.5 or later, which adds an explicit length check (strlen($authTag) !== self::AUTHTAG_LENGTH) before passing the authentication tag to openssl_decrypt(), preventing short-tag bypass (Patch Commit, Release 3.1.5). If your application uses static symmetric AES-GCM keys, immediately rotate all such keys, as the GHASH key may have been recovered by an attacker. Review any encrypted XML data processed prior to patching for signs of unauthorized access. No configuration-based workaround is available; upgrading is the only remediation (GHSA Security Advisory).

Community reactions

The vulnerability was reported by a researcher identified as "Sideni" and disclosed via GitHub's security advisory process on March 13, 2026. Cisco's Duo Access Gateway release notes from June 2026 reference this CVE, indicating downstream product impact and patching activity (Cisco Duo Release Notes). The Hacker Wire noted the disclosure on Mastodon shortly after publication. Community reaction has been moderate, with security aggregators including VulDB and threat intelligence platforms tracking the issue.

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management