← Vulnerability feed

Vulnerability record · CVE-2026-55599 · published 22 June 2026

CVE-2026-55599: Phpseclib server-side request forgery (ssrf) vulnerability

Phpseclib · Phpseclib

phpseclib is a PHP secure communications library. From 0.1.1 until 1.0.30, 2.0.55, and 3.0.54, when an application validates an untrusted X.509 certificate with phpseclib, X509::validateSignature() reads a URL out of that certificate's Authority Information Access (AIA) extension and connects to it. Attacker who supplies certificate fully controls host, port, and path of that connection. URL fetching is enabled by default, and no destination is blocked. An unauthenticated attacker can therefore make a validating server open connections to internal hosts and ports it should never reach, for example loopback 127.0.0.1, cloud metadata address 169.254.169.254, and internal-only services. This is a server-side request forgery (SSRF) caused by an insecure default. This vulnerability is fixed in 1.0.30, 2.0.55, and 3.0.54.

5.8 CVSS 3.1 Medium EPSS 0.21% · top 89.6% CWE-918 · Server-side request forgery (SSRF)
5.8CVSS 3.1 base score
0.21%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
26 Jun 2026Last modified by NVD

Description

phpseclib is a PHP secure communications library. From 0.1.1 until 1.0.30, 2.0.55, and 3.0.54, when an application validates an untrusted X.509 certificate with phpseclib, X509::validateSignature() reads a URL out of that certificate's Authority Information Access (AIA) extension and connects to it. Attacker who supplies certificate fully controls host, port, and path of that connection. URL fetching is enabled by default, and no destination is blocked. An unauthenticated attacker can therefore make a validating server open connections to internal hosts and ports it should never reach, for example loopback 127.0.0.1, cloud metadata address 169.254.169.254, and internal-only services. This is a server-side request forgery (SSRF) caused by an insecure default. This vulnerability is fixed in 1.0.30, 2.0.55, and 3.0.54.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-55599 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.2CVE-2026-32935Phpseclib vulnerabilityphpseclib is a PHP secure communications library. Projects using versions 0.1.1 through 1.0.26, 2.0.0 through 2.0.51, and 3.0.0 through 3.0.49 are vu…EPSS 0.42%7.5CVE-2023-52892Phpseclib interpretation conflict vulnerabilityIn phpseclib before 1.0.22, 2.x before 2.0.46, and 3.x before 3.0.33, some characters in Subject Alternative Name fields in TLS certificates are inco…EPSS 0.38%7.5CVE-2024-27354Phpseclib uncontrolled resource consumption vulnerabilityAn issue was discovered in phpseclib 1.x before 1.0.23, 2.x before 2.0.47, and 3.x before 3.0.36. An attacker can construct a malformed certificate c…EPSS 0.60%7.5CVE-2024-27355Phpseclib uncontrolled resource consumption vulnerabilityAn issue was discovered in phpseclib 1.x before 1.0.23, 2.x before 2.0.47, and 3.x before 3.0.36. When processing the ASN.1 object identifier of a ce…EPSS 0.57%7.5CVE-2023-49316Phpseclib vulnerabilityIn Math/BinaryField.php in phpseclib 3 before 3.0.34, excessively large degrees can lead to a denial of service.EPSS 0.78%7.5CVE-2023-27560Phpseclib vulnerabilityMath/PrimeField.php in phpseclib 3.x before 3.0.19 has an infinite loop with composite primefields.EPSS 0.81%7.5CVE-2021-30130Phpseclib improper verification of cryptographic signature vulnerabilityphpseclib before 2.0.31 and 3.x before 3.0.7 mishandles RSA PKCS#1 v1.5 signature verification.EPSS 1.1%3.7CVE-2026-40194Phpseclib vulnerabilityphpseclib is a PHP secure communications library. Starting in 0.1.1 and prior to 3.0.51, 2.0.53, and 1.0.28, phpseclib\Net\SSH2::get_binary_packet() …EPSS 0.37%

Source: NIST National Vulnerability Database (record CVE-2026-55599), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.