CVE-2026-32313

HIGH

xmlseclibs is Missing AES-GCM Authentication Tag Validation on Encrypted Nodes Allows for Unauthorized Decryption

Title source: cna
STIX 2.1

Description

xmlseclibs is a library written in PHP for working with XML Encryption and Signatures. Prior to 3.1.5, XML nodes encrypted with either aes-128-gcm, aes-192-gcm, or aes-256-gcm lack validation of the authentication tag length. An attacker can use this to brute-force an authentication tag, recover the GHASH key, and decrypt the encrypted nodes. It also allows to forge arbitrary ciphertexts without knowing the encryption key. This vulnerability is fixed in 3.1.5.

Scores

CVSS v3 8.2
EPSS 0.0005
EPSS Percentile 15.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-354
Status published
Products (3)
robrichards/xmlseclibs 0 - 3.1.5Packagist
robrichards/xmlseclibs < 3.1.5
xmlseclibs_project/xmlseclibs < 3.1.5
Published Mar 16, 2026
Tracked Since Mar 16, 2026