Executive brief
xmlseclibs: Missing AES-GCM Authentication Tag Validation on Encrypted Nodes Allows for Unauthorized Decryption
Affected products
- Packagist robrichards/xmlseclibs
Junglewise Threat Intelligence
CVE-2026-32313 · Severity: low · CVSS 3.1 · Published 2026-03-13
Technologies: robrichards/xmlseclibs (Packagist). Vendors: Packagist.
xmlseclibs: Missing AES-GCM Authentication Tag Validation on Encrypted Nodes Allows for Unauthorized Decryption