CVE-2026-44167

EUVD-2026-29724
phpseclib is a PHP secure communications library. Prior to 1.0.29, 2.0.54, and 3.0.52, anyone loading untrusted ASN1 files (eg. X509 certificates, RSA PKCS8 private or public keys, etc). This is a bypass of CVE-2024-27355. This vulnerability is fixed in 1.0.29, 2.0.54, and 3.0.52.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 10.09%
Debian logo
Debian Releases
Debian Product
Codename
php-phpseclib
bookworm
2.0.42-1+deb12u5
fixed
bookworm (security)
vulnerable
bullseye
vulnerable
bullseye (security)
2.0.30-2+deb11u3
fixed
forky
2.0.55-1
fixed
sid
2.0.55-1
fixed
trixie
2.0.48-3+deb13u3
fixed
trixie (security)
vulnerable
php-phpseclib3
bookworm
3.0.19-1+deb12u6
fixed
bookworm (security)
vulnerable
forky
3.0.56-1
fixed
sid
3.0.56-1
fixed
trixie
3.0.43-2+deb13u3
fixed
trixie (security)
vulnerable
phpseclib
bookworm
1.0.20-1+deb12u5
fixed
bookworm (security)
vulnerable
bullseye
vulnerable
bullseye (security)
vulnerable
sid
1.0.30-1
fixed
trixie
1.0.23-6+deb13u3
fixed
trixie (security)
vulnerable
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
php-phpseclib
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
questing
ignored
resolute
needs-triage
xenial
ignored
php-phpseclib3
jammy
needs-triage
noble
needs-triage
questing
ignored
resolute
needs-triage
phpseclib
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
questing
ignored
resolute
needs-triage
xenial
ignored