> USN-8769-1: phpseclib vulnerability
[DATE: 15/09/2026 15:59]
[LANGUAGE: EN]
It was discovered that phpseclib did not perform padding validation in
constant time when using AES in CBC mode. A remote attacker could possibly
use this issue to conduct a padding oracle timing attack and obtain
sensitive information.