Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
CVE-2021-30130
See a problem?
Please try reporting it
to the source
first.
Source
https://nvd.nist.gov/vuln/detail/CVE-2021-30130
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-30130.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2021-30130
Aliases
GHSA-vf4w-fg7r-5v94
Downstream
DEBIAN-CVE-2021-30130
DLA-3197-1
DLA-3198-1
UBUNTU-CVE-2021-30130
USN-7404-1
Published
2021-04-06T15:15:13Z
Modified
2025-10-15T12:57:11.960382Z
Severity
7.5 (High)
CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS Calculator
Summary
[none]
Details
phpseclib before 2.0.31 and 3.x before 3.0.7 mishandles RSA PKCS#1 v1.5 signature verification.
References
https://github.com/phpseclib/phpseclib/pull/1635
https://github.com/phpseclib/phpseclib/releases/tag/2.0.31
https://github.com/phpseclib/phpseclib/releases/tag/3.0.7
https://lists.debian.org/debian-lts-announce/2022/11/msg00024.html
https://lists.debian.org/debian-lts-announce/2022/11/msg00025.html
Affected packages
Git
/
github.com/phpseclib/phpseclib
Affected ranges
Type
GIT
Repo
https://github.com/phpseclib/phpseclib
Events
Introduced
0
Unknown introduced commit / All previous commits are affected
Fixed
233a920cb38636a43b18d428f9a8db1f0a1a08f4
Fixed
d369510df0ebd5e1a5d0fe3d4d23c55fa87a403d
Affected versions
0.*
0.1.0
0.1.1
0.1.2
0.1.5
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.10
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
1.*
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
2.*
2.0.0
2.0.1
2.0.10
2.0.11
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.4
2.0.5
2.0.6
2.0.7
2.0.9
CVE-2021-30130 - OSV