In phpseclib before 1.0.22, 2.x before 2.0.46, and 3.x before 3.0.33, some characters in Subject Alternative Name fields in TLS certificates are incorrectly allowed to have a special meaning in regular expressions (such as a + wildcard), leading to name confusion in X.509 certificate host verification.
Cite this page
CVE-2023-52892. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2023-52892
Use CWE-436, Phpseclib vendor hub and Phpseclib product page to widen CVE-2023-52892 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-32935, CVE-2024-27355 and CVE-2024-27354 for nearby disclosures in the same product family.