Vulnerability GHSA-86w9-cpqp-85rv

High Risk
HIGH RISK
CVSS Score: 7.5
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
28 days ago
September 03, 2026 at 09:31 PM UTC
node-forge RSA PKCS#1 v1.5 signature verification accepts extra nested DigestAlgorithm elements
0.1.2 - 1.4.0
0.1.2 - 1.4.0

Summary

node-forge RSA PKCS#1 v1.5 signature verification accepts extra nested DigestAlgorithm elements

Details

node-forge through 1.4.0 fails to validate element count in nested DigestAlgorithm sequences during RSA PKCS#1 v1.5 signature verification. Attackers can embed garbage bytes inside the DigestAlgorithm sequence to forge valid signatures for arbitrary messages using low-exponent RSA keys. This is an incomplete fix for CVE-2026-33894.

Impacted packages

Timeline

Published
28 days ago
September 03, 2026 at 09:31 PM UTC
Last Modified
5 hours ago
October 01, 2026 at 09:40 PM UTC