CVE-2026-32935

NameCVE-2026-32935
Descriptionphpseclib is a PHP secure communications library. Projects using versions 1.0.26 and below, 2.0.0 through 2.0.51, and 3.0.0 through 3.0.49 are vulnerable to a to padding oracle timing attack when using AES in CBC mode. This issue has been fixed in versions 1.0.27, 2.0.52 and 3.0.50.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-4518-1, DSA-6185-1, DSA-6186-1, DSA-6187-1
Debian Bugs1131482, 1131483, 1131484

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
php-phpseclib (PTS)bullseye2.0.30-2+deb11u2vulnerable
bullseye (security)2.0.30-2+deb11u1vulnerable
bookworm2.0.42-1+deb12u2vulnerable
bookworm (security)2.0.42-1+deb12u3fixed
trixie2.0.48-3vulnerable
trixie (security)2.0.48-3+deb13u1fixed
forky, sid2.0.52-1fixed
php-phpseclib3 (PTS)bookworm3.0.19-1+deb12u3vulnerable
bookworm (security)3.0.19-1+deb12u4fixed
trixie3.0.43-2vulnerable
trixie (security)3.0.43-2+deb13u1fixed
forky, sid3.0.50-1fixed
phpseclib (PTS)bullseye1.0.19-3+deb11u2vulnerable
bullseye (security)1.0.19-3+deb11u3fixed
bookworm1.0.20-1+deb12u2vulnerable
bookworm (security)1.0.20-1+deb12u3fixed
trixie1.0.23-6vulnerable
trixie (security)1.0.23-6+deb13u1fixed
sid1.0.27-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
php-phpseclibsourcebookworm2.0.42-1+deb12u3DSA-6186-1
php-phpseclibsourcetrixie2.0.48-3+deb13u1DSA-6186-1
php-phpseclibsource(unstable)2.0.52-11131483
php-phpseclib3sourcebookworm3.0.19-1+deb12u4DSA-6187-1
php-phpseclib3sourcetrixie3.0.43-2+deb13u1DSA-6187-1
php-phpseclib3source(unstable)3.0.50-11131482
phpseclibsourcebullseye1.0.19-3+deb11u3DLA-4518-1
phpseclibsourcebookworm1.0.20-1+deb12u3DSA-6185-1
phpseclibsourcetrixie1.0.23-6+deb13u1DSA-6185-1
phpseclibsource(unstable)1.0.27-11131484

Notes

https://github.com/phpseclib/phpseclib/security/advisories/GHSA-94g3-g5v7-q4jg
Fixed by: https://github.com/phpseclib/phpseclib/commit/ccc21aef71eb170e9bf819b167e67d1fd9e6e788 (3.0.50, 2.0.52, 1.0.27)

Search for package or bug name: Reporting problems