CVE-2026-55599: phpseclib: X.509 certificate validation sends attacker-controlled outbound requests (server-side request forgery) via Authority Information Access

Published Jun 22, 2026
·
Updated

phpseclib is a PHP secure communications library. From 0.1.1 until 1.0.30, 2.0.55, and 3.0.54, when an application validates an untrusted X.509 certificate with phpseclib, X509::validateSignature() reads a URL out of that certificate's Authority Information Access (AIA) extension and connects to it. Attacker who supplies certificate fully controls host, port, and path of that connection. URL fetching is enabled by default, and no destination is blocked. An unauthenticated attacker can therefore make a validating server open connections to internal hosts and ports it should never reach, for example loopback 127.0.0.1, cloud metadata address 169.254.169.254, and internal-only services. This is a server-side request forgery (SSRF) caused by an insecure default. This vulnerability is fixed in 1.0.30, 2.0.55, and 3.0.54.

Affected Software

4 affected components
packagist/phpseclib/phpseclib>=0.1.1<1.0.30, >=0.1.1<2.0.55, >=0.1.1<3.0.54
phpseclib phpseclib>=0.1.1<1.0.30
phpseclib phpseclib>=2.0.0<2.0.55
phpseclib phpseclib>=3.0.0<3.0.54

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade phpseclib to a version that resolves this vulnerability.

    Fixed in 1.0.30
  2. Upgrade

    Upgrade phpseclib to a version that resolves this vulnerability.

    Fixed in 2.0.55
  3. Upgrade

    Upgrade phpseclib to a version that resolves this vulnerability.

    Fixed in 3.0.54
  4. Configuration

    Disable URL fetching during X.509 certificate validation so X509::validateSignature() does not connect to URLs read from the certificate's Authority Information Access (AIA) extension.

    phpseclib (X.509 certificate validation) URL fetching from certificate Authority Information Access (AIA) = disabled

Event History

Jun 22, 2026
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-55599?

CVE-2026-55599 has a medium severity rating of 5.8.

2

What is CVE-2026-55599?

CVE-2026-55599 is a vulnerability in phpseclib that allows for server-side request forgery through untrusted X.509 certificate validation.

3

How do I fix CVE-2026-55599?

To mitigate CVE-2026-55599, upgrade phpseclib to a version later than 1.0.30, 2.0.55, and 3.0.54.

4

What types of applications are affected by CVE-2026-55599?

Applications using phpseclib versions from 0.1.1 to 1.0.30, 2.0.55, and 3.0.54 for X.509 certificate validation are affected.

5

What kind of attack can CVE-2026-55599 facilitate?

CVE-2026-55599 can facilitate server-side request forgery (SSRF) attacks by allowing unauthorized outbound requests.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203