phpseclib has a CVE-2024-27355 mitigation bypass — OID amplification DoS in ASN1::decodeOID()
Package
Affected versions
>= 2.0.0, <= 2.0.53
>= 3.0.0, <= 3.0.51
>= 0.1.1, <= 1.0.28
Patched versions
2.0.54
3.0.52
1.0.29
Description
Published to the GitHub Advisory Database
May 5, 2026
Reviewed
May 5, 2026
Published by the National Vulnerability Database
May 12, 2026
Last updated
May 13, 2026
Impact
Anyone loading untrusted ASN1 files (eg. X509 certificates, RSA PKCS8 private or public keys, etc)
Patches
phpseclib/phpseclib@d53d202
Workarounds
No.
References
phpseclib/phpseclib@d53d202
References