In phpseclib before 1.0.22, 2.x before 2.0.46, and 3.x before 3.0.33, some characters in Subject Alternative Name fields in TLS certificates are incorrectly allowed to have a special meaning in regular expressions (such as a + wildcard), leading to name confusion in X.509 certificate host verification.
Metrics
Affected Vendors & Products
References
History
Wed, 22 Oct 2025 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:phpseclib:phpseclib:*:*:*:*:*:*:*:* |
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 21 Aug 2024 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-436 | |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published: 2024-06-27T00:00:00
Updated: 2024-08-21T20:02:23.834Z
Reserved: 2024-06-27T00:00:00
Link: CVE-2023-52892
Updated: 2024-08-02T23:18:41.296Z
Status : Analyzed
Published: 2024-06-27T22:15:10.277
Modified: 2025-10-22T20:40:45.620
Link: CVE-2023-52892
No data.