Linuxsecurity Critical Info Disclosure Vulnerability in phpseclib for Fedora 42 and 43
Article Content
- •CVE-2026-32935 allows information disclosure via padding oracle timing attacks.
- •Affected systems include Fedora 42 and 43 using phpseclib library.
- •Updates to phpseclib versions 2.0.52 and 3.0.50 are available to mitigate the risk.
A critical information disclosure vulnerability (CVE-2026-32935) was identified in the phpseclib library, affecting Fedora 42 and 43. The vulnerability allows attackers to exploit a padding oracle timing attack when using AES in CBC mode, potentially disclosing sensitive information. The issue was published on 2026-03-20 and has been addressed in updates for both Fedora versions. Fedora 43 has been updated to version 3.0.50, while Fedora 42 has been updated to version 2.0.52 to mitigate the risk. Users are advised to apply the updates immediately to protect against potential exploitation. The updates can be installed using the 'dnf' package manager. The vulnerability impacts systems utilizing the affected versions of phpseclib, which is widely used for cryptographic operations in PHP applications. Failure to update may leave systems vulnerable to attacks that exploit this flaw.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Fedora and CVE-2026-32935 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical phpseclib Vulnerabilities Expose Sensitive Data and Cause DoS Multiple vulnerabilities were discovered in phpseclib, a library for arbitrary-precision integer arithmetic. Notably, CVE-2026-32935 involves a lack of constant-time padding validation in AES CBC mode, potentially allowing remote attackers to obtain sensitive information. CVE-2026-40194 highlights a similar issue with…
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…