Vulnerabilities (CVE)

Filtered by vendor Phpseclib Subscribe
Filtered by product Phpseclib
Total 5 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-27354 2 Debian, Phpseclib 2 Debian Linux, Phpseclib 2025-09-15 N/A 7.5 HIGH
An issue was discovered in phpseclib 1.x before 1.0.23, 2.x before 2.0.47, and 3.x before 3.0.36. An attacker can construct a malformed certificate containing an extremely large prime to cause a denial of service (CPU consumption for an isPrime primality check). NOTE: this issue was introduced when attempting to fix CVE-2023-27560.
CVE-2024-27355 2 Debian, Phpseclib 2 Debian Linux, Phpseclib 2025-09-15 N/A 7.5 HIGH
An issue was discovered in phpseclib 1.x before 1.0.23, 2.x before 2.0.47, and 3.x before 3.0.36. When processing the ASN.1 object identifier of a certificate, a sub identifier may be provided that leads to a denial of service (CPU consumption for decodeOID).
CVE-2023-27560 1 Phpseclib 1 Phpseclib 2025-03-06 N/A 7.5 HIGH
Math/PrimeField.php in phpseclib 3.x before 3.0.19 has an infinite loop with composite primefields.
CVE-2023-49316 1 Phpseclib 1 Phpseclib 2024-11-21 N/A 7.5 HIGH
In Math/BinaryField.php in phpseclib 3 before 3.0.34, excessively large degrees can lead to a denial of service.
CVE-2021-30130 2 Debian, Phpseclib 2 Debian Linux, Phpseclib 2024-11-21 5.0 MEDIUM 7.5 HIGH
phpseclib before 2.0.31 and 3.x before 3.0.7 mishandles RSA PKCS#1 v1.5 signature verification.