PT-2026-84455 · Phpseclib · Phpseclib

CVE-2026-84308

·

Published

2026-09-01

·

Updated

2026-09-09

CVSS v3.1

6.3

Medium

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions phpseclib versions prior to 3.0.57 phpseclib versions prior to 4.0.1
Description Pure-PHP X25519 scalar multiplication in phpseclib/Math/PrimeField/Integer.php performs data-dependent conditional modular reductions in the add() and subtract() functions. During the Montgomery ladder in phpseclib/Crypt/EC/BaseCurves/Montgomery.php, the reduction behavior of each step depends on the secret scalar prefix. This creates timing and libgmp call-count observations that can reveal a reused 251-bit clamped private scalar. The phpseclib/Crypt/EC/Formats/Keys/MontgomeryPrivate.php derivation path invokes this multiplication without a native-engine check, and phpseclib/Crypt/EC/Formats/Keys/PKCS8.php reaches it when ext-sodium is unavailable. Exploitation requires a reused or long-lived X25519 private key, knowledge of the corresponding public key, execution of the pure-PHP path, and a local observer capable of resolving individual ladder steps or libgmp entry-point calls. Ephemeral X25519 keys are not affected. Recovery of the scalar permanently compromises operations that reuse that key.
Recommendations Update to version 3.0.57 or later. Update to version 4.0.1 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-84308
GHSA-Q97C-8QH3-FPC6

Affected Products

Phpseclib