« Volver al listado

CVE-2026-40194

Estado: ModificadaBaja (3.7)—

phpseclib is a PHP secure communications library. Starting in 0.1.1 and prior to 3.0.51, 2.0.53, and 1.0.28, phpseclib\Net\SSH2::get_binary_packet() uses PHP's != operator to compare a received SSH packet HMAC against the locally computed HMAC. != on equal-length binary strings in PHP uses memcmp(), which short-circuits on the first differing byte. This is a real variable-time comparison (CWE-208), proven by scaling benchmarks. This vulnerability is fixed in 3.0.51, 2.0.53, and 1.0.28.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-40194",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-40194",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-04-13T15:28:24.152831Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 3.7,
          "attackVector": "NETWORK",
          "baseSeverity": "LOW",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.2
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "phpseclib",
          "product": "phpseclib",
          "versions": [
            {
              "status": "affected",
              "version": ">= 0.1.1, < 1.0.28"
            },
            {
              "status": "affected",
              "version": ">= 2.0.0, < 2.0.53"
            },
            {
              "status": "affected",
              "version": ">= 3.0.0, < 3.0.51"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-04-10T21:16:27.583",
  "references": [
    {
      "url": "https://github.com/phpseclib/phpseclib/commit/ffe48b6b1b1af6963327f0a5330e3aa004a194ac",
      "tags": [
        "Patch"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/phpseclib/phpseclib/releases/tag/1.0.28",
      "tags": [
        "Release Notes"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/phpseclib/phpseclib/releases/tag/2.0.53",
      "tags": [
        "Release Notes"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/phpseclib/phpseclib/releases/tag/3.0.51",
      "tags": [
        "Release Notes"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/phpseclib/phpseclib/security/advisories/GHSA-r854-jrxh-36qx",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/phpseclib/phpseclib/security/advisories/GHSA-r854-jrxh-36qx",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-208"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "phpseclib is a PHP secure communications library. Starting in 0.1.1 and prior to 3.0.51, 2.0.53, and 1.0.28, phpseclib\\Net\\SSH2::get_binary_packet() uses PHP's != operator to compare a received SSH packet HMAC against the locally computed HMAC. != on equal-length binary strings in PHP uses memcmp(), which short-circuits on the first differing byte. This is a real variable-time comparison (CWE-208), proven by scaling benchmarks. This vulnerability is fixed in 3.0.51, 2.0.53, and 1.0.28."
    }
  ],
  "lastModified": "2026-06-17T10:44:51.140",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:phpseclib:phpseclib:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8315BEB0-7CC2-4BF7-8951-086898B9D909",
              "versionEndIncluding": "1.0.27"
            },
            {
              "criteria": "cpe:2.3:a:phpseclib:phpseclib:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "88F1EA13-1048-43B5-8AE5-52D81EE17470",
              "versionEndExcluding": "2.0.53",
              "versionStartIncluding": "2.0.0"
            },
            {
              "criteria": "cpe:2.3:a:phpseclib:phpseclib:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "595DB51F-4A57-4D49-A951-E45590487A83",
              "versionEndExcluding": "3.0.51",
              "versionStartIncluding": "3.0.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security-advisories@github.com"
}