{"record":{"id":"c340a1e9193de825","repo":"laravel/framework","slug":"unable-to-use-tag-because-the-cipher-algorithm-doe","errorCode":null,"errorMessage":"Unable to use tag because the cipher algorithm does not support AEAD.","messagePattern":"Unable to use tag because the cipher algorithm does not support AEAD\\.","errorType":"exception","errorClass":"DecryptException","httpStatus":null,"severity":"error","filePath":"src/Illuminate/Encryption/Encrypter.php","lineNumber":324,"sourceCode":"        );\n    }\n\n    /**\n     * Ensure the given tag is a valid tag given the selected cipher.\n     *\n     * @param  string  $tag\n     * @return void\n     *\n     * @throws \\Illuminate\\Contracts\\Encryption\\DecryptException\n     */\n    protected function ensureTagIsValid($tag)\n    {\n        if (self::$supportedCiphers[strtolower($this->cipher)]['aead'] && strlen($tag) !== 16) {\n            throw new DecryptException('Could not decrypt the data.');\n        }\n\n        if (! self::$supportedCiphers[strtolower($this->cipher)]['aead'] && is_string($tag)) {\n            throw new DecryptException('Unable to use tag because the cipher algorithm does not support AEAD.');\n        }\n    }\n\n    /**\n     * Determine if we should validate the MAC while decrypting.\n     *\n     * @return bool\n     */\n    protected function shouldValidateMac()\n    {\n        return ! self::$supportedCiphers[strtolower($this->cipher)]['aead'];\n    }\n\n    /**\n     * Determine if the given value appears to be encrypted by this encrypter.\n     *\n     * @param  mixed  $value\n     * @return bool","sourceCodeStart":306,"sourceCodeEnd":342,"githubUrl":"https://github.com/laravel/framework/blob/e0f6eb3518ac29fbbca8529e97d0df7fc9f24481/src/Illuminate/Encryption/Encrypter.php#L306-L342","documentation":"Thrown by Encrypter::ensureTagIsValid() when the configured cipher is non-AEAD (aes-128-cbc / aes-256-cbc) but a string tag was supplied to decryption. CBC algorithms cannot use an authentication tag, so passing one indicates a caller/API mismatch. Laravel refuses to silently ignore the tag because mixing cipher modes would be insecure.","triggerScenarios":"Calling Encrypter::decrypt($payload, $deserialize = true, $tag = '...') (or decryptString with a tag) while $this->cipher resolves to one of the CBC entries in $supportedCiphers where 'aead' is false.","commonSituations":"Code written against an AES-GCM deployment is reused on an environment whose APP_CIPHER is aes-256-cbc; downgrading cipher for compatibility while still forwarding a tag; copying example code that always passes a tag.","solutions":["Stop passing the $tag argument when decrypting with a CBC cipher, or pass null.","Align both ends on an AEAD cipher (set APP_CIPHER=aes-256-gcm) if tag-based authentication is required.","Audit Encrypter construction to confirm the cipher matches the producer of the payload."],"exampleFix":"// before: CBC cipher configured but tag supplied\n$plain = $encrypter->decrypt($payload, true, $tag);\n\n// after: do not pass a tag for non-AEAD ciphers\n$plain = $encrypter->decrypt($payload);","handlingStrategy":"validation","validationCode":"$cipher = strtolower(config('app.cipher'));\n$aead = in_array($cipher, ['aes-128-gcm','aes-256-gcm'], true);\nif (! $aead && $tag !== null) {\n    throw new InvalidArgumentException('Tag provided but cipher is non-AEAD.');\n}","typeGuard":"function supportsAead(string $cipher): bool {\n    return in_array(strtolower($cipher), ['aes-128-gcm','aes-256-gcm'], true);\n}","tryCatchPattern":"use Illuminate\\Contracts\\Encryption\\DecryptException;\ntry {\n    $plain = $encrypter->decrypt($payload, true, $aead ? $tag : null);\n} catch (DecryptException $e) {\n    report($e);\n    return null;\n}","preventionTips":["Decide once whether to use AEAD and apply it everywhere.","Do not pass $tag by default; pass it only when cipher is AEAD.","Keep APP_CIPHER consistent across environments.","Document the cipher choice in your security runbook."],"tags":["encryption","decrypt","aead","cipher-mismatch"],"backgroundTag":null,"analyzedSha":"e0f6eb3518ac29fbbca8529e97d0df7fc9f24481","analyzedAt":"2026-08-11T20:52:37.562Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}