Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 13 Jul 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 13 Jul 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Phalcon
Phalcon cphalcon |
|
| Vendors & Products |
Phalcon
Phalcon cphalcon |
Fri, 10 Jul 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Phalcon is a high-performance, full-stack PHP framework. Prior to 5.14.1, Phalcon\Encryption\Crypt::decrypt compares the attacker-supplied HMAC tag against the freshly computed HMAC using PHP/Zephir identity comparison, which lowers to a byte-wise comparison that returns early on the first differing byte. This observable timing discrepancy can allow an attacker to recover a valid tag byte-by-byte and attach it to a chosen IV and ciphertext so that decrypt() accepts tampered encrypted content as authentic. This issue is fixed in version 5.14.1. | |
| Title | Phalcon: Non-constant-time HMAC verification in `Encryption\Crypt::decrypt` (timing side-channel) | |
| Weaknesses | CWE-208 CWE-347 |
|
| References |
|
|
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-07-13T18:01:40.822Z
Reserved: 2026-06-15T23:07:33.233Z
Link: CVE-2026-54736
Updated: 2026-07-13T18:01:36.681Z
Status : Deferred
Published: 2026-07-10T22:16:42.970
Modified: 2026-07-13T19:21:55.683
Link: CVE-2026-54736
No data.
OpenCVE Enrichment
Updated: 2026-08-01T12:15:03Z