CVE-2026-32935: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-32935 is a padding oracle timing attack vulnerability in phpseclib, a PHP secure communications library, affecting its AES-CBC mode unpadding implementation. It impacts versions 0.1.1 through 1.0.26, 2.0.0 through 2.0.51, and 3.0.0 through 3.0.49. The vulnerability was published on March 19, 2026, by the library's maintainer (terrafrost) via a GitHub Security Advisory, with NVD publication following on March 20, 2026. It carries a CVSS v3.1 base score of 5.9 (Medium) and a CVSS v4.0 base score of 8.2 (High) (GitHub Advisory, Red Hat Bugzilla).

Technical details

The root cause is classified as CWE-208 (Observable Timing Discrepancy): the _unpad() function in phpseclib/Crypt/Base.php used a short-circuit logical OR (||) when validating padding bytes, causing the operation to complete in measurably different amounts of time depending on whether the padding length was zero versus invalid. This timing side-channel allows an attacker to submit crafted ciphertexts and observe response timing differences to iteratively deduce the correct padding byte, enabling a classic padding oracle attack against AES-CBC encrypted data. The fix, committed as ccc21ae, replaces the short-circuit || with a bitwise | operator to ensure constant-time evaluation regardless of the padding value (GitHub Commit, GitHub Advisory). Exploitation requires network access and the ability to submit multiple crafted ciphertexts to an oracle endpoint, but no authentication or user interaction is needed.

Impact

Successful exploitation allows an unauthenticated remote attacker to recover plaintext data from AES-CBC encrypted ciphertexts without possessing the encryption key, resulting in a high confidentiality impact. There is no integrity or availability impact — the attack is purely a passive decryption oracle. Applications using phpseclib for encrypting sensitive data (e.g., session tokens, credentials, personal information) are at risk of data exposure if they expose a decryption endpoint observable by the attacker (GitHub Advisory, Red Hat Bugzilla).

Exploitability

No public proof-of-concept exploit code has been identified, and there is no evidence of active in-the-wild exploitation at this time (GitHub Advisory). The EPSS score is approximately 0.013% (4th percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires high attack complexity due to the need for precise timing measurements and multiple oracle queries, limiting opportunistic exploitation.

Exploitation steps

  1. Identify target: Locate an application using phpseclib (versions ≤1.0.26, 2.0.0–2.0.51, or 3.0.0–3.0.49) that decrypts AES-CBC ciphertexts and returns a response (even an error) observable by the attacker, such as a web endpoint that decrypts user-supplied data.
  2. Capture or craft a target ciphertext: Obtain a valid AES-CBC ciphertext to decrypt (e.g., an encrypted session token or cookie).
  3. Submit crafted ciphertexts: Send modified ciphertexts to the target endpoint, systematically manipulating the last byte of the second-to-last ciphertext block to probe padding validity.
  4. Measure timing differences: Record the response time for each request. Due to the non-constant-time _unpad() implementation, valid padding (length > 0 and ≤ block size) takes a measurably different time than invalid padding (length = 0), leaking a single bit of information per query.
  5. Iterate byte-by-byte: Use the timing oracle to recover each plaintext byte, working from the last byte of each block backwards, repeating for each block of the ciphertext.
  6. Recover plaintext: After sufficient queries (typically 256 × block_size per block), reconstruct the full plaintext without knowledge of the encryption key (GitHub Advisory, GitHub Commit).

Indicators of compromise

  • Network: High volume of repeated requests to a decryption endpoint from a single IP or small IP range, with systematically varying ciphertext values (e.g., only the last 1–2 bytes of a block differ across requests).
  • Logs: Application or web server logs showing thousands of decryption requests in rapid succession, many resulting in padding error responses; unusual patterns of near-identical requests differing only in the last bytes of a ciphertext parameter.
  • Application Behavior: Elevated rate of decryption failures or padding error exceptions logged by the phpseclib-based application, potentially surfaced in PHP error logs or application-level logging.

Mitigation and workarounds

Upgrade phpseclib to the patched versions: 1.0.27 (for 1.x users), 2.0.52 (for 2.x users), or 3.0.50 (for 3.x users). As an immediate workaround without upgrading, switch from AES-CBC mode to a non-vulnerable authenticated encryption mode such as AES-CTR, AES-CFB, or AES-OFB, which are not susceptible to padding oracle attacks. Organizations should also review any sensitive data previously encrypted with vulnerable versions, as confidentiality may have been compromised if an oracle endpoint was exposed (GitHub Advisory, GitHub Commit).

Community reactions

Red Hat tracked the issue via Bugzilla (Bug 2449428) and assessed it at medium severity. Debian issued security advisories (DSA-6185-1, DSA-6186-1, and DLA-4518-1) for phpseclib packages across stable and LTS releases. Fedora also released updates for affected phpseclib packages. Cisco's Duo Access Gateway and Duo Desktop products were noted as incorporating phpseclib and addressed the issue in their June 2026 release notes (Red Hat Bugzilla).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

phpseclib: 1.0.20-1+deb12u3

Fixed

sid

phpseclib: 1.0.27-1

Fixed

trixie

phpseclib: 1.0.23-6+deb13u1

Fixed

Ubuntu

Fixed

bionic (esm-apps)

php-phpseclib: 2.0.9-1ubuntu0.1~esm3

Fixed

devel

php-phpseclib

Not Affected

focal (esm-apps)

php-phpseclib: 2.0.23-2ubuntu0.1~esm3

Fixed

jammy

php-phpseclib

Affected

jammy (esm-apps)

php-phpseclib: 2.0.36-1ubuntu0.1~esm3

Fixed

noble

php-phpseclib

Affected

noble (esm-apps)

php-phpseclib: 2.0.47-1ubuntu0.1~esm1

Fixed

resolute

php-phpseclib

Affected

Alpine

Fixed

edge

cacti: 1.2.31-0

Fixed

Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management