Phpseclib is a pure-PHP cryptography and security library embedded across a large range of applications and server environments, giving its flaws outsized reach despite a narrow product footprint. Its vulnerability profile centers on the recurring weakness classes that affect cryptographic implementations: timing discrepancies, resource-consumption issues, excessive iteration in validation loops, improper signature verification, and interpretation conflicts in protocol handling—issues inherent to the complexity of reimplementing security primitives in a high-level language. Defenders should prioritize inventory of downstream applications that bundle this library, as remediation typically depends on those applications rebuilding and deploying updates; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Phpseclib over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-55599MEDIUM phpseclib is a PHP secure communications library. From 0.1.1 until 1.0.30, 2.0.55, and 3.0.54, when an application validates an untrusted X.509 certificate with phpseclib, X509::va | Jun 22, 2026 | 5.8 | 24 | NO | NO |
CVE-2023-27560HIGH Math/PrimeField.php in phpseclib 3.x before 3.0.19 has an infinite loop with composite primefields. | Mar 3, 2023 | 7.5 | 24 | NO | NO |
CVE-2021-30130HIGH phpseclib before 2.0.31 and 3.x before 3.0.7 mishandles RSA PKCS#1 v1.5 signature verification. | Apr 6, 2021 | 7.5 | 24 | NO | NO |
CVE-2024-27355HIGH An issue was discovered in phpseclib 1.x before 1.0.23, 2.x before 2.0.47, and 3.x before 3.0.36. When processing the ASN.1 object identifier of a certificate, a sub identifier may | Mar 1, 2024 | 7.5 | 22 | NO | NO |
CVE-2026-32935MEDIUM phpseclib is a PHP secure communications library. Projects using versions 0.1.1 through 1.0.26, 2.0.0 through 2.0.51, and 3.0.0 through 3.0.49 are vulnerable to a to padding oracle | Mar 20, 2026 | 5.9 | 21 | NO | NO |
CVE-2023-52892HIGH In phpseclib before 1.0.22, 2.x before 2.0.46, and 3.x before 3.0.33, some characters in Subject Alternative Name fields in TLS certificates are incorrectly allowed to have a speci | Jun 27, 2024 | 7.5 | 20 | NO | NO |
CVE-2024-27354HIGH An issue was discovered in phpseclib 1.x before 1.0.23, 2.x before 2.0.47, and 3.x before 3.0.36. An attacker can construct a malformed certificate containing an extremely large pr | Mar 1, 2024 | 7.5 | 20 | NO | NO |
CVE-2023-49316HIGH In Math/BinaryField.php in phpseclib 3 before 3.0.34, excessively large degrees can lead to a denial of service. | Nov 27, 2023 | 7.5 | 20 | NO | NO |
phpseclib is a PHP secure communications library. Starting in 0.1.1 and prior to 3.0.51, 2.0.53, and 1.0.28, phpseclib\Net\SSH2::get_binary_packet() uses PHP's != operator to compa | Apr 10, 2026 | 3.7 | 18 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Phpseclib.
Media articles that mention a CVE ID that affects a product developed by Phpseclib — matched by CVE ID, not by vendor name.