Ghostwire / Intelligence Feed / Coverage

CVE-2026-40194 - phpseclib has a variable-time HMAC comparison in SSH2::get_binary_packet() using != instead of hash_equals()

CVE Feed cybersecurity · April 10, 2026 · Original source
CVE ID :CVE-2026-40194 Published : April 10, 2026, 9:16 p.m. | 2 hours, 52 minutes ago Description :phpseclib is a PHP secure communications library. Prior to 3.0.51, 2.0.53, and 1.0.28, php...

Related Vulnerabilities

Related Coverage

Threat Actors