Phpseclib

Phpseclib

9 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.03%
  • Veröffentlicht 12.05.2026 17:22:14
  • Zuletzt bearbeitet 13.05.2026 18:24:31

phpseclib is a PHP secure communications library. Prior to 1.0.29, 2.0.54, and 3.0.52, anyone loading untrusted ASN1 files (eg. X509 certificates, RSA PKCS8 private or public keys, etc). This is a bypass of CVE-2024-27355. This vulnerability is fixed...

  • EPSS 0.01%
  • Veröffentlicht 10.04.2026 20:24:06
  • Zuletzt bearbeitet 08.05.2026 16:16:10

phpseclib is a PHP secure communications library. Starting in 0.1.1 and prior to 3.0.51, 2.0.53, and 1.0.28, phpseclib\Net\SSH2::get_binary_packet() uses PHP's != operator to compare a received SSH packet HMAC against the locally computed HMAC. != on...

  • EPSS 0.02%
  • Veröffentlicht 20.03.2026 03:16:00
  • Zuletzt bearbeitet 08.05.2026 16:16:10

phpseclib is a PHP secure communications library. Projects using versions 0.1.1 through 1.0.26, 2.0.0 through 2.0.51, and 3.0.0 through 3.0.49 are vulnerable to a to padding oracle timing attack when using AES in CBC mode. This issue has been fixed i...

Exploit
  • EPSS 0.22%
  • Veröffentlicht 27.06.2024 22:15:10
  • Zuletzt bearbeitet 22.10.2025 20:40:45

In phpseclib before 1.0.22, 2.x before 2.0.46, and 3.x before 3.0.33, some characters in Subject Alternative Name fields in TLS certificates are incorrectly allowed to have a special meaning in regular expressions (such as a + wildcard), leading to n...

  • EPSS 0.2%
  • Veröffentlicht 01.03.2024 23:15:08
  • Zuletzt bearbeitet 15.09.2025 17:58:58

An issue was discovered in phpseclib 1.x before 1.0.23, 2.x before 2.0.47, and 3.x before 3.0.36. An attacker can construct a malformed certificate containing an extremely large prime to cause a denial of service (CPU consumption for an isPrime prima...

  • EPSS 0.34%
  • Veröffentlicht 01.03.2024 23:15:08
  • Zuletzt bearbeitet 15.09.2025 17:17:49

An issue was discovered in phpseclib 1.x before 1.0.23, 2.x before 2.0.47, and 3.x before 3.0.36. When processing the ASN.1 object identifier of a certificate, a sub identifier may be provided that leads to a denial of service (CPU consumption for de...

  • EPSS 0.15%
  • Veröffentlicht 27.11.2023 18:15:07
  • Zuletzt bearbeitet 21.11.2024 08:33:13

In Math/BinaryField.php in phpseclib 3 before 3.0.34, excessively large degrees can lead to a denial of service.

  • EPSS 0.27%
  • Veröffentlicht 03.03.2023 06:15:08
  • Zuletzt bearbeitet 06.03.2025 21:15:13

Math/PrimeField.php in phpseclib 3.x before 3.0.19 has an infinite loop with composite primefields.

  • EPSS 0.2%
  • Veröffentlicht 06.04.2021 15:15:13
  • Zuletzt bearbeitet 21.11.2024 06:03:22

phpseclib before 2.0.31 and 3.x before 3.0.7 mishandles RSA PKCS#1 v1.5 signature verification.