CVE-2026-32935: phpseclib's AES-CBC unpadding susceptible to padding oracle timing attack
(updated )
Those using AES in CBC mode may be susceptible to a padding oracle timing attack.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-32935 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →