← Vulnerability feed

Vulnerability record · CVE-2023-27560 · published 3 March 2023

CVE-2023-27560: Phpseclib vulnerability

Phpseclib · Phpseclib

Math/PrimeField.php in phpseclib 3.x before 3.0.19 has an infinite loop with composite primefields.

7.5 CVSS 3.1 High EPSS 0.81% · top 44.9% CWE-835 · CWE-835
7.5CVSS 3.1 base score
0.81%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Math/PrimeField.php in phpseclib 3.x before 3.0.19 has an infinite loop with composite primefields.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-27560 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.2CVE-2026-32935Phpseclib vulnerabilityphpseclib is a PHP secure communications library. Projects using versions 0.1.1 through 1.0.26, 2.0.0 through 2.0.51, and 3.0.0 through 3.0.49 are vu…EPSS 0.42%7.5CVE-2023-52892Phpseclib interpretation conflict vulnerabilityIn phpseclib before 1.0.22, 2.x before 2.0.46, and 3.x before 3.0.33, some characters in Subject Alternative Name fields in TLS certificates are inco…EPSS 0.38%7.5CVE-2024-27354Phpseclib uncontrolled resource consumption vulnerabilityAn issue was discovered in phpseclib 1.x before 1.0.23, 2.x before 2.0.47, and 3.x before 3.0.36. An attacker can construct a malformed certificate c…EPSS 0.60%7.5CVE-2024-27355Phpseclib uncontrolled resource consumption vulnerabilityAn issue was discovered in phpseclib 1.x before 1.0.23, 2.x before 2.0.47, and 3.x before 3.0.36. When processing the ASN.1 object identifier of a ce…EPSS 0.57%7.5CVE-2023-49316Phpseclib vulnerabilityIn Math/BinaryField.php in phpseclib 3 before 3.0.34, excessively large degrees can lead to a denial of service.EPSS 0.78%7.5CVE-2021-30130Phpseclib improper verification of cryptographic signature vulnerabilityphpseclib before 2.0.31 and 3.x before 3.0.7 mishandles RSA PKCS#1 v1.5 signature verification.EPSS 1.1%5.8CVE-2026-55599Phpseclib server-side request forgery (ssrf) vulnerabilityphpseclib is a PHP secure communications library. From 0.1.1 until 1.0.30, 2.0.55, and 3.0.54, when an application validates an untrusted X.509 certi…EPSS 0.21%3.7CVE-2026-40194Phpseclib vulnerabilityphpseclib is a PHP secure communications library. Starting in 0.1.1 and prior to 3.0.51, 2.0.53, and 1.0.28, phpseclib\Net\SSH2::get_binary_packet() …EPSS 0.37%

Source: NIST National Vulnerability Database (record CVE-2023-27560), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.