Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Highjenny

#26627of 56,330
9.8Total CVSS
Vulnerabilities · 1
PT-2026-29574
9.8
2026-04-01
Auth0 · Auth0/Laravel0-Auth0 · CVE-2026-34236
Auth0-PHP versions 8.0.0 through 8.18.0 Description: The Auth0-PHP SDK uses insufficient entropy for cookie encryption. This could allow attackers to brute-force the encryption key and forge session cookies. This affects applications using Auth0-PHP versions 8.0.0 through 8.18.0, as well as applications using Auth0/symfony, Auth0/laravel0-auth0, or Auth0/wordpress which rely on the Auth0-PHP SDK. Recommendations: Upgrade Auth0/Auth0-PHP to version 8.19.0 or greater.