phpseclib guardrails needed on OID length
Package
Affected versions
>= 2.0.0, <= 2.0.46
>= 3.0.0, <= 3.0.35
>= 0.1.1, <= 1.0.22
Patched versions
2.0.47
3.0.36
1.0.23
Description
Published to the GitHub Advisory Database
May 8, 2026
Reviewed
May 8, 2026
Impact
Any application using that loads untrusted ASN1 files (eg. X509 certificates, RSA PKCS8 private or public keys, etc).
Patches
phpseclib/phpseclib@e325310
Workarounds
No.
Resources
phpseclib/phpseclib@e325310
https://www.usenix.org/system/files/conference/usenixsecurity25/sec25cycle1-prepub-599-shi-bing.pdf
References