Auth0-PHP is a PHP SDK for Auth0 Authentication and Management APIs. From version 8.0.0 to before version 8.19.0, in applications built with the Auth0 PHP SDK, cookies are encrypted with insufficient entropy, which may result in threat actors brute-forcing the encryption key and forging session cookies. This issue has been patched in version 8.19.0.
References
| Link | Resource |
|---|---|
| https://github.com/auth0/auth0-PHP/releases/tag/8.19.0 | Product Release Notes |
| https://github.com/auth0/auth0-PHP/security/advisories/GHSA-w3wc-44p4-m4j7 | Vendor Advisory |
Configurations
History
07 Apr 2026, 20:20
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/auth0/auth0-PHP/releases/tag/8.19.0 - Product, Release Notes | |
| References | () https://github.com/auth0/auth0-PHP/security/advisories/GHSA-w3wc-44p4-m4j7 - Vendor Advisory | |
| CPE | cpe:2.3:a:auth0:auth0-php:*:*:*:*:*:*:*:* | |
| First Time |
Auth0
Auth0 auth0-php |
01 Apr 2026, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-01 18:16
Updated : 2026-04-07 20:20
NVD link : CVE-2026-34236
Mitre link : CVE-2026-34236
CVE.ORG link : CVE-2026-34236
JSON object : View
Products Affected
auth0
- auth0-php
CWE
CWE-331
Insufficient Entropy
