PT-2026-85226 · Npm · Node-Forge

·

CVE-2026-85393

·

Published

2026-03-26

·

Updated

2026-09-03

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions node-forge versions prior to 1.4.1
Description An issue exists during RSA PKCS#1 v1.5 signature verification where the software fails to validate the element count in nested DigestAlgorithm sequences. This allows attackers to embed garbage bytes within the DigestAlgorithm sequence to forge valid signatures for arbitrary messages when low-exponent RSA keys are used.
Recommendations Update node-forge to version 1.4.1 or later.

Exploit

Fix

RCE

Improper Verification of Cryptographic Signature

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-85393
GHSA-PPP5-5V6C-4JWP

Affected Products

Node-Forge