Skip to content
Fedora 42 php-phpseclib3 Important Security Alert CVE-2026

Fedora 42 php-phpseclib3 Important Security Alert CVE-2026

Linuxsecurity •LinuxSecurity Advisories • March 30, 2026

MIT-licensed pure-PHP implementations of an arbitrary-precision integer arithmetic library, fully PKCS#1 (v2.1) compliant RSA, DES, 3DES, RC4, Rijndael, AES, Blowfish, Twofish, SSH-1, SSH-2, SFTP, and X.509 Update Information : Update to v3.0.50; contains fix for CVE-2026-32935

MIT-licensed pure-PHP implementations of an arbitrary-precision integer

arithmetic library, fully PKCS#1 (v2.1) compliant RSA, DES, 3DES, RC4,

Rijndael, AES, Blowfish, Twofish, SSH-1, SSH-2, SFTP, and X.509

Update to v3.0.50; contains fix for CVE-2026-32935

* Sat Mar 21 2026 Artur Frenszek-Iwicki - 3.0.50-1 - Update to v3.0.50

* Sat Mar 21 2026 Artur Frenszek-Iwicki - 3.0.50-1 - Update to v3.0.50

[ 1 ] Bug #2448961 - php-phpseclib3-3.0.50 is available [ 2 ] Bug #2449634 - CVE-2026-32935 php-phpseclib3: phpseclib: Information disclosure via padding oracle timing attack when using AES in CBC mode [fedora-42]

[ 1 ] Bug #2448961 - php-phpseclib3-3.0.50 is available [ 2 ] Bug #2449634 - CVE-2026-32935 php-phpseclib3: phpseclib: Information disclosure via padding oracle timing attack when using AES in CBC mode [fedora-42]

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-65fdd15133' at the command line. For more information, refer to the dnf documentation available at

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-65fdd15133' at the command line. For more information, refer to the dnf documentation available at

Extracted Entities

Companies (1)