Skip to content

phpseclib has a variable-time HMAC comparison in SSH2::get_binary_packet() using != instead of hash_equals()

Low severity GitHub Reviewed Published Apr 10, 2026 in phpseclib/phpseclib • Updated Apr 10, 2026

No open alerts for this advisory

Give feedback on Dependabot alerts