{"record":{"id":"b66acdda3ebbd951","repo":"laravel/framework","slug":"could-not-decrypt-the-data","errorCode":null,"errorMessage":"Could not decrypt the data.","messagePattern":"Could not decrypt the data\\.","errorType":"exception","errorClass":"DecryptException","httpStatus":null,"severity":"critical","filePath":"src/Illuminate/Encryption/Encrypter.php","lineNumber":201,"sourceCode":"            );\n\n            if ($decrypted !== false) {\n                break;\n            }\n        }\n\n        if ($this->shouldValidateMac() && $validKey === null) {\n            throw new DecryptException('The MAC is invalid.');\n        }\n\n        if ($this->shouldValidateMac()) {\n            $decrypted = \\openssl_decrypt(\n                $payload['value'], strtolower($this->cipher), $validKey, 0, $iv, $tag ?? ''\n            );\n        }\n\n        if (($decrypted ?? false) === false) {\n            throw new DecryptException('Could not decrypt the data.');\n        }\n\n        return $unserialize ? unserialize($decrypted) : $decrypted;\n    }\n\n    /**\n     * Decrypt the given string without unserialization.\n     *\n     * @param  string  $payload\n     * @return string\n     *\n     * @throws \\Illuminate\\Contracts\\Encryption\\DecryptException\n     */\n    public function decryptString($payload)\n    {\n        return $this->decrypt($payload, false);\n    }\n","sourceCodeStart":183,"sourceCodeEnd":219,"githubUrl":"https://github.com/laravel/framework/blob/e0f6eb3518ac29fbbca8529e97d0df7fc9f24481/src/Illuminate/Encryption/Encrypter.php#L183-L219","documentation":"After MAC validation (or if MAC validation is disabled), Encrypter calls openssl_decrypt; if it returns false, DecryptException('Could not decrypt the data.') is thrown. Unlike the MAC failure this means the payload passed structural and integrity checks but the cipher operation itself failed — typically because the IV/tag length is wrong for the algorithm or the value was corrupted in a way that still passes the MAC check (extremely rare) or because the cipher/key pair is inconsistent with the one that produced the value.","triggerScenarios":"Calling Crypt::decrypt() with a valid MAC but an IV/tag that openssl_decrypt rejects; mismatched cipher between encrypt and decrypt (e.g. data encrypted as aes-256-gcm then decrypted with aes-256-cbc configuration); corrupted IV/tag bytes from cookie truncation.","commonSituations":"Changing app.cipher between encrypt and decrypt without re-encrypting; proxy/CDN stripping bytes from the payload; PHP/OpenSSL version differences between the encrypting system and the decrypting system; corrupted stored ciphertext in a database column with wrong collation.","solutions":["Ensure the cipher configuration at decrypt time matches what was used to encrypt (config('app.cipher') consistent across environments).","Store/transport ciphertext in base64 form within binary-safe columns and cookies; avoid collation that re-encodes the bytes.","If you recently changed ciphers, re-encrypt all existing values using the previous cipher before switching.","Verify the payload length and IV/tag byte lengths are intact end-to-end."],"exampleFix":"// before\n// data encrypted under aes-256-gcm, now decrypted under aes-256-cbc config\n\n// after — keep cipher consistent end-to-end\n// config/app.php (both environments): 'cipher' => 'aes-256-gcm',\n// re-encrypt legacy payloads during a one-time migration if changing cipher","handlingStrategy":"try-catch","validationCode":"// ensure cipher consistency between encrypt and decrypt environments\nif (config('app.cipher') !== $expectedCipher) {\n    throw new RuntimeException('Cipher mismatch — cannot safely decrypt.');\n}","typeGuard":null,"tryCatchPattern":"use Illuminate\\Contracts\\Encryption\\DecryptException;\n\ntry {\n    return Crypt::decrypt($payload);\n} catch (DecryptException $e) {\n    if (str_contains($e->getMessage(), 'Could not decrypt')) {\n        // likely cipher/IV/tag corruption — log and treat as invalid\n        report($e);\n        return null;\n    }\n    throw $e;\n}","preventionTips":["Keep app.cipher identical across all environments that exchange encrypted data.","Store ciphertext in binary-safe columns (BLOB / VARBINARY) or base64-encoded text.","Re-encrypt existing values when changing cipher rather than decrypting across versions."],"tags":["encryption","security","decryption","openssl","configuration"],"backgroundTag":null,"analyzedSha":"e0f6eb3518ac29fbbca8529e97d0df7fc9f24481","analyzedAt":"2026-08-11T20:52:37.562Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}