CVE Explorer
CVE-2026-32313
xmlseclibs is a library written in PHP for working with XML Encryption and Signatures. Prior to 3.1.5, XML nodes encrypted with either aes-128-gcm, aes-192-gcm, or aes-256-gcm lack validation of the authentication tag length. An attacker can use this to brute-force an authentication tag, recover the GHASH key, and decrypt the encrypted nodes. It also allows to forge arbitrary ciphertexts without knowing the encryption key. This vulnerability is fixed in 3.1.5.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"xmlseclibs","vendor":"robrichards","versions":[{"status":"affected","version":"< 3.1.5"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:0197502ef9c835686aa4e840a610a28e68edb26e2d5aa1189cf5accdb1f12e18 · sha256:ce5a2076ccecb3d3… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":8.2,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:0197502ef9c835686aa4e840a610a28e68edb26e2d5aa1189cf5accdb1f12e18 · sha256:ce5a2076ccecb3d3… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-354","description":"CWE-354: Improper Validation of Integrity Check Value","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:0197502ef9c835686aa4e840a610a28e68edb26e2d5aa1189cf5accdb1f12e18 · sha256:ce5a2076ccecb3d3… · /containers/cna/problemTypes/0/descriptions/0
Source references
3 source assertions{"name":"https://github.com/robrichards/xmlseclibs/commit/03062be78178cbb5e8f605cd255dc32a14981f92","tags":["x_refsource_MISC"],"url":"https://github.com/robrichards/xmlseclibs/commit/03062be78178cbb5e8f605cd255dc32a14981f92"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:0197502ef9c835686aa4e840a610a28e68edb26e2d5aa1189cf5accdb1f12e18 · sha256:ce5a2076ccecb3d3… · /containers/cna/references/1
{"name":"https://github.com/robrichards/xmlseclibs/releases/tag/3.1.5","tags":["x_refsource_MISC"],"url":"https://github.com/robrichards/xmlseclibs/releases/tag/3.1.5"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:0197502ef9c835686aa4e840a610a28e68edb26e2d5aa1189cf5accdb1f12e18 · sha256:ce5a2076ccecb3d3… · /containers/cna/references/2
{"name":"https://github.com/robrichards/xmlseclibs/security/advisories/GHSA-4v26-v6cg-g6f9","tags":["x_refsource_CONFIRM"],"url":"https://github.com/robrichards/xmlseclibs/security/advisories/GHSA-4v26-v6cg-g6f9"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:0197502ef9c835686aa4e840a610a28e68edb26e2d5aa1189cf5accdb1f12e18 · sha256:ce5a2076ccecb3d3… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.