Vulnerability Description
phpseclib is a PHP secure communications library. Prior to 1.0.29, 2.0.54, and 3.0.52, anyone loading untrusted ASN1 files (eg. X509 certificates, RSA PKCS8 private or public keys, etc). This is a bypass of CVE-2024-27355. This vulnerability is fixed in 1.0.29, 2.0.54, and 3.0.52.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/phpseclib/phpseclib/commit/d53d2021bcb9f6a04d5d44ec99e6bbef21
- https://github.com/phpseclib/phpseclib/security/advisories/GHSA-3qpq-r242-jqj7
FAQ
What is CVE-2026-44167?
CVE-2026-44167 is a vulnerability with a CVSS score of 7.5 (HIGH). phpseclib is a PHP secure communications library. Prior to 1.0.29, 2.0.54, and 3.0.52, anyone loading untrusted ASN1 files (eg. X509 certificates, RSA PKCS8 private or public keys, etc). This is a byp...
How severe is CVE-2026-44167?
CVE-2026-44167 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-44167?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.