THREAT OPS › Threat News › [GHSA] GHSA-q97c-8qh3-fpc6 (medium) — phpseclib — non-constant-time X25519 scalar multiplication permits full private-key recovery
[GHSA] GHSA-q97c-8qh3-fpc6 (medium) — phpseclib — non-constant-time X25519 scalar multiplication permits full private-key recovery
GHSA-q97c-8qh3-fpc6 Severity: medium CVE: CVE-2026-84308
phpseclib — non-constant-time X25519 scalar multiplication permits full private-key recovery
The pure-PHP X25519 scalar multiplication in phpseclib is not constant-time. Field addition and subtraction each perform a **data-dependent conditional modular reduction**, so the cost of each Montgomery-ladder step is a linear function of that ste
Indicators of compromise
- cc7250b611f520e809131aab0931503457c44d8cbfb10d535251c6fec5f62a2bsha256
- CVE-2026-84308cve
- https://www.aueb.gr/en/faculty_page/stergiopoulos-georgiosurl
- geostergiop@aueb.gremail
Original source: https://github.com/advisories/GHSA-q97c-8qh3-fpc6