{"id":"GHSA-w3wc-44p4-m4j7","summary":"Auth0 PHP SDK has Insufficient Entropy in Cookie Encryption","details":"### Impact\nIn applications built with the Auth0 PHP SDK, cookies are encrypted with insufficient entropy, which may result in threat actors brute-forcing the encryption key and forging session cookies.\n\n### Am I Affected?\nConsumers are affected if their application meets the following preconditions:\n- Their application is using the Auth0-PHP SDK, versions between 8.0.0 and 8.18.0\n- Their application is using the Auth0-PHP SDK, or the following SDKs that rely on the Auth0-PHP SDK:\n    - Auth0/symfony,\n    - Auth0/laravel0-auth0, or\n    - Auth0/wordpress\n\n### Resolution\nUpgrade Auth0/Auth0-PHP to version 8.19.0 or greater.","aliases":["CVE-2026-34236"],"modified":"2026-04-01T20:56:28.595224Z","published":"2026-04-01T20:29:26Z","database_specific":{"nvd_published_at":"2026-04-01T18:16:30Z","cwe_ids":["CWE-331"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-04-01T20:29:26Z"},"references":[{"type":"WEB","url":"https://github.com/auth0/auth0-PHP/security/advisories/GHSA-w3wc-44p4-m4j7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34236"},{"type":"PACKAGE","url":"https://github.com/auth0/auth0-PHP"},{"type":"WEB","url":"https://github.com/auth0/auth0-PHP/releases/tag/8.19.0"}],"affected":[{"package":{"name":"auth0/auth0-php","ecosystem":"Packagist","purl":"pkg:composer/auth0/auth0-php"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"8.0.0"},{"fixed":"8.19.0"}]}],"versions":["8.0.0","8.0.1","8.0.2","8.0.3","8.0.4","8.0.5","8.0.6","8.1.0","8.10.0","8.11.0","8.11.1","8.12.0","8.13.0","8.14.0","8.15.0","8.16.0","8.17.0","8.18.0","8.2.0","8.2.1","8.3.0","8.3.1","8.3.2","8.3.3","8.3.4","8.3.5","8.3.6","8.3.7","8.3.8","8.4.0","8.5.0","8.6.0","8.7.0","8.7.1","8.8.0","8.9.0","8.9.1","8.9.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-w3wc-44p4-m4j7/GHSA-w3wc-44p4-m4j7.json","last_known_affected_version_range":"\u003c= 8.18.0"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N"}]}