
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-32935 is a padding oracle timing attack vulnerability in phpseclib, a PHP secure communications library, affecting its AES-CBC mode unpadding implementation. It impacts versions 0.1.1 through 1.0.26, 2.0.0 through 2.0.51, and 3.0.0 through 3.0.49. The vulnerability was published on March 19, 2026, by the library's maintainer (terrafrost) via a GitHub Security Advisory, with NVD publication following on March 20, 2026. It carries a CVSS v3.1 base score of 5.9 (Medium) and a CVSS v4.0 base score of 8.2 (High) (GitHub Advisory, Red Hat Bugzilla).
The root cause is classified as CWE-208 (Observable Timing Discrepancy): the _unpad() function in phpseclib/Crypt/Base.php used a short-circuit logical OR (||) when validating padding bytes, causing the operation to complete in measurably different amounts of time depending on whether the padding length was zero versus invalid. This timing side-channel allows an attacker to submit crafted ciphertexts and observe response timing differences to iteratively deduce the correct padding byte, enabling a classic padding oracle attack against AES-CBC encrypted data. The fix, committed as ccc21ae, replaces the short-circuit || with a bitwise | operator to ensure constant-time evaluation regardless of the padding value (GitHub Commit, GitHub Advisory). Exploitation requires network access and the ability to submit multiple crafted ciphertexts to an oracle endpoint, but no authentication or user interaction is needed.
Successful exploitation allows an unauthenticated remote attacker to recover plaintext data from AES-CBC encrypted ciphertexts without possessing the encryption key, resulting in a high confidentiality impact. There is no integrity or availability impact — the attack is purely a passive decryption oracle. Applications using phpseclib for encrypting sensitive data (e.g., session tokens, credentials, personal information) are at risk of data exposure if they expose a decryption endpoint observable by the attacker (GitHub Advisory, Red Hat Bugzilla).
No public proof-of-concept exploit code has been identified, and there is no evidence of active in-the-wild exploitation at this time (GitHub Advisory). The EPSS score is approximately 0.013% (4th percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires high attack complexity due to the need for precise timing measurements and multiple oracle queries, limiting opportunistic exploitation.
_unpad() implementation, valid padding (length > 0 and ≤ block size) takes a measurably different time than invalid padding (length = 0), leaking a single bit of information per query.Upgrade phpseclib to the patched versions: 1.0.27 (for 1.x users), 2.0.52 (for 2.x users), or 3.0.50 (for 3.x users). As an immediate workaround without upgrading, switch from AES-CBC mode to a non-vulnerable authenticated encryption mode such as AES-CTR, AES-CFB, or AES-OFB, which are not susceptible to padding oracle attacks. Organizations should also review any sensitive data previously encrypted with vulnerable versions, as confidentiality may have been compromised if an oracle endpoint was exposed (GitHub Advisory, GitHub Commit).
Red Hat tracked the issue via Bugzilla (Bug 2449428) and assessed it at medium severity. Debian issued security advisories (DSA-6185-1, DSA-6186-1, and DLA-4518-1) for phpseclib packages across stable and LTS releases. Fedora also released updates for affected phpseclib packages. Cisco's Duo Access Gateway and Duo Desktop products were noted as incorporating phpseclib and addressed the issue in their June 2026 release notes (Red Hat Bugzilla).
Fix availability across major Linux distributions and their releases.
bookworm
phpseclib: 1.0.20-1+deb12u3
sid
phpseclib: 1.0.27-1
trixie
phpseclib: 1.0.23-6+deb13u1
bionic (esm-apps)
php-phpseclib: 2.0.9-1ubuntu0.1~esm3
devel
php-phpseclib
focal (esm-apps)
php-phpseclib: 2.0.23-2ubuntu0.1~esm3
jammy
php-phpseclib
jammy (esm-apps)
php-phpseclib: 2.0.36-1ubuntu0.1~esm3
noble
php-phpseclib
noble (esm-apps)
php-phpseclib: 2.0.47-1ubuntu0.1~esm1
resolute
php-phpseclib
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."