Junglewise Threat Intelligence

CVE-2026-34236: Auth0 PHP SDK has Insufficient Entropy in Cookie Encryption

CVE-2026-34236 · Severity: low · CVSS 3.1 · Published 2026-04-01

Technologies: auth0/auth0-php (Packagist). Vendors: Packagist.

Executive brief

Auth0 PHP SDK has Insufficient Entropy in Cookie Encryption

Affected products

  • Packagist auth0/auth0-php

Related threats