PT-2026-85226 · Npm · Node-Forge
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
node-forge versions prior to 1.4.1
Description
An issue exists during RSA PKCS#1 v1.5 signature verification where the software fails to validate the element count in nested DigestAlgorithm sequences. This allows attackers to embed garbage bytes within the DigestAlgorithm sequence to forge valid signatures for arbitrary messages when low-exponent RSA keys are used.
Recommendations
Update node-forge to version 1.4.1 or later.
Exploit
Fix
RCE
Improper Verification of Cryptographic Signature
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Node-Forge