Loading
phpseclib is a PHP secure communications library. Projects using versions 1.0.26 and below, 2.0.0 through 2.0.51, and 3.0.0 through 3.0.49 are vulnerable to a to padding oracle timing attack when using AES in CBC mode. This issue has been fixed in versions 1.0.27, 2.0.52 and 3.0.50.
Cite this page
CVE-2026-32935. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2026-32935
Use CWE-208, Phpseclib vendor hub and Phpseclib product page to widen CVE-2026-32935 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2023-52892, CVE-2024-27355 and CVE-2024-27354 for nearby disclosures in the same product family.