Server-Side Request Forgery (SSRF) Affecting phpseclib package, versions <1.0.30-1


Severity

Recommended
low

Based on default assessment until relevant scores are available.

Threat Intelligence

EPSS
0.16% (6th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DEBIANUNSTABLE-PHPSECLIB-17428800
  • published23 Jun 2026
  • disclosed22 Jun 2026

Introduced: 22 Jun 2026

CVE-2026-55599  (opens in a new tab)
CWE-918  (opens in a new tab)

How to fix?

Upgrade Debian:unstable phpseclib to version 1.0.30-1 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream phpseclib package and not the phpseclib package as distributed by Debian. See How to fix? for Debian:unstable relevant fixed versions and status.

phpseclib is a PHP secure communications library. From 0.1.1 until 1.0.30, 2.0.55, and 3.0.54, when an application validates an untrusted X.509 certificate with phpseclib, X509::validateSignature() reads a URL out of that certificate's Authority Information Access (AIA) extension and connects to it. Attacker who supplies certificate fully controls host, port, and path of that connection. URL fetching is enabled by default, and no destination is blocked. An unauthenticated attacker can therefore make a validating server open connections to internal hosts and ports it should never reach, for example loopback 127.0.0.1, cloud metadata address 169.254.169.254, and internal-only services. This is a server-side request forgery (SSRF) caused by an insecure default. This vulnerability is fixed in 1.0.30, 2.0.55, and 3.0.54.