CVE-2026-55599

EUVD-2026-38348
phpseclib is a PHP secure communications library. From 0.1.1 until 1.0.30, 2.0.55, and 3.0.54, when an application validates an untrusted X.509 certificate with phpseclib, X509::validateSignature() reads a URL out of that certificate's Authority Information Access (AIA) extension and connects to it. Attacker who supplies certificate fully controls host, port, and path of that connection. URL fetching is enabled by default, and no destination is blocked. An unauthenticated attacker can therefore make a validating server open connections to internal hosts and ports it should never reach, for example loopback 127.0.0.1, cloud metadata address 169.254.169.254, and internal-only services. This is a server-side request forgery (SSRF) caused by an insecure default. This vulnerability is fixed in 1.0.30, 2.0.55, and 3.0.54.
SSRF
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.8 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 5.19%
Affected Products (NVD)
VendorProductVersion
phpseclibphpseclib
0.1.1 ≤
𝑥
< 1.0.30
phpseclibphpseclib
2.0.0 ≤
𝑥
< 2.0.55
phpseclibphpseclib
3.0.0 ≤
𝑥
< 3.0.54
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
php-phpseclib
bookworm
postponed
bookworm (security)
vulnerable
bullseye
postponed
bullseye (security)
2.0.30-2+deb11u3
fixed
forky
2.0.55-1
fixed
sid
2.0.55-1
fixed
trixie
no-dsa
trixie (security)
vulnerable
php-phpseclib3
bookworm
postponed
bookworm (security)
vulnerable
forky
3.0.55-1
fixed
sid
3.0.55-1
fixed
trixie
no-dsa
trixie (security)
vulnerable
phpseclib
bookworm
postponed
bookworm (security)
vulnerable
bullseye
postponed
bullseye (security)
vulnerable
sid
1.0.30-1
fixed
trixie
no-dsa
trixie (security)
vulnerable
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
phpseclib
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
questing
ignored
resolute
needs-triage