Junglewise Threat Intelligence

CVE-2026-32313: xmlseclibs: Missing AES-GCM Authentication Tag Validation on Encrypted Nodes Allows for Unauthorized Decryption

CVE-2026-32313 · Severity: low · CVSS 3.1 · Published 2026-03-13

Technologies: robrichards/xmlseclibs (Packagist). Vendors: Packagist.

Executive brief

xmlseclibs: Missing AES-GCM Authentication Tag Validation on Encrypted Nodes Allows for Unauthorized Decryption

Affected products

  • Packagist robrichards/xmlseclibs

Related threats