CVE-2026-40194 - phpseclib has a variable-time HMAC comparison in SSH2::get_binary_packet() using != instead of hash_equals()
CVE ID :CVE-2026-40194
Published : April 10, 2026, 9:16 p.m. | 2 hours, 52 minutes ago
Description :phpseclib is a PHP secure communications library. Prior to 3.0.51, 2.0.53, and 1.0.28, php...
Related Vulnerabilities
- CVE-2026-40199: Net::CIDR::Lite versions before 0.23 for Perl mishandles IPv4 mapped IPv6 addresses, which may allow MEDIUM
- CVE-2026-22750: When configuring SSL bundles in Spring Cloud Gateway by using the configuration property spring.ssl. HIGH
- CVE-2026-40194: phpseclib has a variable-time HMAC comparison in SSH2::get_binary_packet() using != instead of hash_ LOW
- CVE-2026-40198: Net::CIDR::Lite versions before 0.23 for Perl does not validate IPv6 group count, which may allow IP MEDIUM
- CVE-2026-35670: OpenClaw before 2026.3.22 contains a webhook reply delivery vulnerability that allows attackers to r MEDIUM
Related Coverage
Threat Actors