


Perceptive Security
SOC/SIEM Consultancy

xmlseclibs is a library written in PHP for working with XML Encryption and Signatures. Prior to 3.1.5, XML nodes encrypted with either aes-128-gcm, aes-192-gcm,…
Published:
15 March 2026 at 23:00:00
Alert date:
16 March 2026 at 16:21:26
Source:
nvd.nist.gov
Web Technologies, Supply Chain & Dependencies
xmlseclibs PHP library for XML Encryption and Signatures contains a critical vulnerability in versions prior to 3.1.5. The vulnerability affects XML nodes encrypted with AES-GCM algorithms (aes-128-gcm, aes-192-gcm, aes-256-gcm) due to lack of authentication tag length validation. Attackers can exploit this to brute-force authentication tags, recover GHASH keys, decrypt encrypted nodes, and forge arbitrary ciphertexts without knowing the encryption key. The vulnerability has been patched in version 3.1.5.
Technical details
Mitigation steps:
Affected products:
xmlseclibs
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-32313
https://github.com/robrichards/xmlseclibs/commit/03062be78178cbb5e8f605cd255dc32a14981f92
https://github.com/robrichards/xmlseclibs/releases/tag/3.1.5
https://github.com/robrichards/xmlseclibs/security/advisories/GHSA-4v26-v6cg-g6f9
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
