Php Short Gcm Auth Tag
Description
This detector identifies uses of short authentication tags in PHP cryptographic operations, specifically with OpenSSL and phpseclib libraries. Short authentication tags (typically less than 128 bits) in Galois/Counter Mode (GCM) encryption provide insufficient cryptographic security and can be vulnerable to forgery attacks.
Detection Strategy
• The detector checks if phpseclib cryptographic library is imported in the PHP code
• For each selected code node, it examines if the code contains OpenSSL encrypt operations with short authentication tags
• When phpseclib is imported, it also checks for calls to getTag() methods that return short authentication tags
• A vulnerability is reported when either short OpenSSL encryption tags or short phpseclib getTag calls are found in the code
Vulnerable code example
<?php
use phpseclib3\Crypt\AES;
function unsafeEncryption($data, $key) {
$iv = random_bytes(12);
$tag = '';
// VULNERABLE: tag_length is 8 bytes, below the 12-byte security minimum...✅ Secure code example
<?php
use phpseclib3\Crypt\AES;
function safeEncryption($data, $key) {
$iv = random_bytes(12);
$tag = '';
// SAFE: Use default 16-byte tag length for strong authentication...Search for vulnerabilities in your apps for free with Fluid Attacks' automated security testing! Start your 21-day free trial and discover the benefits of the Continuous Hacking Essential plan. If you prefer the Advanced plan, which includes the expertise of Fluid Attacks' hacking team, fill out this contact form.