THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-q97c-8qh3-fpc6 (medium) — phpseclib — non-constant-time X25519 scalar multiplication permits full private-key recovery

[GHSA] GHSA-q97c-8qh3-fpc6 (medium) — phpseclib — non-constant-time X25519 scalar multiplication permits full private-key recovery

highgithub_advisoriesPublished 2026-09-08

GHSA-q97c-8qh3-fpc6 Severity: medium CVE: CVE-2026-84308

phpseclib — non-constant-time X25519 scalar multiplication permits full private-key recovery

The pure-PHP X25519 scalar multiplication in phpseclib is not constant-time. Field addition and subtraction each perform a **data-dependent conditional modular reduction**, so the cost of each Montgomery-ladder step is a linear function of that ste

Indicators of compromise

Original source: https://github.com/advisories/GHSA-q97c-8qh3-fpc6