CVE-2026-32600

HIGH

xml-security is Missing AES-GCM Authentication Tag Validation on Encrypted Nodes Allows for Unauthorized Decryption

Title source: cna
STIX 2.1

Description

xml-security is a library that implements XML signatures and encryption. Prior to versions 2.3.1 and 1.13.9, XML nodes encrypted with either aes-128-gcm, aes-192-gcm, or aes-256-gcm lack validation of the authentication tag length. An attacker can use this to brute-force an authentication tag, recover the GHASH key, and decrypt the encrypted nodes. It also allows to forge arbitrary ciphertexts without knowing the encryption key. This vulnerability is fixed in 2.3.1 and 1.13.9.

Scores

CVSS v3 8.2
EPSS 0.0002
EPSS Percentile 5.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-354
Status published
Products (3)
simplesamlphp/xml-security < 1.13.9 (2 CPE variants)
simplesamlphp/xml-security 2.0.0 - 2.3.1Packagist
simplesamlphp/xml-security >= 2.0.0, < 2.3.1
Published Mar 16, 2026
Tracked Since Mar 16, 2026