Notice USN-8830-1, published on September 28, 2026 and presented as an automatic translation of content from the Ubuntu Security feed, describes three phpseclib vulnerabilities. Consult the original notice in Ubuntu's security publication and check that the translation preserves the technical details.
The first flaw is validation of padding without constant-time behavior when using AES in CBC mode. According to the notice, a remote attacker could possibly exploit it to obtain confidential information. It is identified as CVE-2026-32935.
The second flaw concerns a comparison, also without constant-time behavior, of SSH packet authentication codes; the notice associates it with possible exposure of confidential information by a remote attacker (CVE-2026-40194). The third is the lack of a proper length limit for object identifiers when parsing ASN.1 data, which could lead to excessive resource consumption and denial of service (CVE-2026-44167).
To assess the impact, compare the CVE identifiers and descriptions with the original notice and security information relevant to your use of phpseclib. The supplied text gives no affected versions or fixes; do not assume them. If you use AI to study or apply the notice, avoid submitting code, credentials, or identifiable internal data.