Back to vendor advisories
Ubuntu Security NoticesUSN-8830-1

USN-8830-1: phpseclib vulnerabilities

It was discovered that phpseclib did not perform constant-time padding validation when using AES in CBC mode. A remote attacker could possibly use this issue to obtain sensitive information. (CVE-2026-32935) It was discovered that phpseclib did not use a constant-time comparison when validating SSH packet authentication codes. A remote attacker could possibly use this issue to obtain sensitive information. (CVE-2026-40194) It was discovered that phpseclib did not properly limit object identifier lengths when parsing ASN.1 data. An attacker could possibly use this issue to cause phpseclib to use excessive resources, leading to a denial of service. (CVE-2026-44167)

Not listedCVSS not listedNot listed severity
Scope

What the vendor says is affected

The collected bulletin did not provide a separate affected-products list. Check the original bulletin before making an exposure decision.

Timeline

When this advisory changed

  1. Published by Ubuntu

    The publication date reported by the vendor.

  2. Added to SecurityAlert

    We collected the advisory from the official source.

Vulnerabilities

CVEs named in this advisory