CVE-2023-52892

7.5 HIGH
Published: June 27, 2024 Modified: October 22, 2025
View on NVD

Description

In phpseclib before 1.0.22, 2.x before 2.0.46, and 3.x before 3.0.33, some characters in Subject Alternative Name fields in TLS certificates are incorrectly allowed to have a special meaning in regular expressions (such as a + wildcard), leading to name confusion in X.509 certificate host verification.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

CVSS v3.x Details

0.0 Low Medium High Critical 10.0
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
https://github.com/phpseclib/phpseclib/issues/1943
Source: cve@mitre.org
Exploit Issue Tracking
https://github.com/phpseclib/phpseclib/issues/1943
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit Issue Tracking
https://github.com/phpseclib/phpseclib/releases/tag/3.0.33
Source: af854a3a-2127-422b-91ae-364da2661108
Release Notes
https://github.com/x509-name-testing/name_testing_artifacts
Source: af854a3a-2127-422b-91ae-364da2661108
Not Applicable

8 reference(s) from NVD

Quick Stats

CVSS v3 Score
7.5 / 10.0
EPSS (Exploit Probability)
0.2%
40th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

phpseclib