Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2026-85393

Опубликовано: 07 сент. 2026
Источник: msrc
CVSS3: 7.5
EPSS Низкий

Описание

node-forge through 1.4.0 RSA PKCS#1 v1.5 Signature Forgery via Nested DigestAlgorithm Padding

Обновления

ПродуктСтатьяОбновление
azl3 python-tensorboard 2.16.2-6 on Azure Linux 3.0

Показывать по

EPSS

Процентиль: 9%
0.00197
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
12 дней назад

node-forge through 1.4.0 fails to validate element count in nested DigestAlgorithm sequences during RSA PKCS#1 v1.5 signature verification. Attackers can embed garbage bytes inside the DigestAlgorithm sequence to forge valid signatures for arbitrary messages using low-exponent RSA keys. This is an incomplete fix for CVE-2026-33894.

CVSS3: 7.5
redhat
13 дней назад

A flaw was found in node-forge. This vulnerability allows a remote attacker to forge valid RSA PKCS#1 v1.5 signatures for arbitrary messages. The flaw occurs because the software fails to properly validate the element count in nested DigestAlgorithm sequences during signature verification. By embedding specially crafted data, an attacker can bypass signature validation, leading to potential integrity compromise.

CVSS3: 7.5
nvd
13 дней назад

node-forge through 1.4.0 fails to validate element count in nested DigestAlgorithm sequences during RSA PKCS#1 v1.5 signature verification. Attackers can embed garbage bytes inside the DigestAlgorithm sequence to forge valid signatures for arbitrary messages using low-exponent RSA keys. This is an incomplete fix for CVE-2026-33894.

CVSS3: 7.5
debian
13 дней назад

node-forge through 1.4.0 fails to validate element count in nested Dig ...

CVSS3: 7.5
github
12 дней назад

node-forge through 1.4.0 fails to validate element count in nested DigestAlgorithm sequences during RSA PKCS#1 v1.5 signature verification. Attackers can embed garbage bytes inside the DigestAlgorithm sequence to forge valid signatures for arbitrary messages using low-exponent RSA keys. This is an incomplete fix for CVE-2026-33894.

EPSS

Процентиль: 9%
0.00197
Низкий

7.5 High

CVSS3