Executive brief
Auth0 PHP SDK has Insufficient Entropy in Cookie Encryption
Affected products
- Packagist auth0/auth0-php
Junglewise Threat Intelligence
CVE-2026-34236 · Severity: low · CVSS 3.1 · Published 2026-04-01
Technologies: auth0/auth0-php (Packagist). Vendors: Packagist.
Auth0 PHP SDK has Insufficient Entropy in Cookie Encryption