Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-33896

Опубликовано: 27 мар. 2026
Источник: nvd
CVSS3: 7.4
CVSS3: 9.1
EPSS Низкий

Описание

Forge (also called node-forge) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, pki.verifyCertificateChain() does not enforce RFC 5280 basicConstraints requirements when an intermediate certificate lacks both the basicConstraints and keyUsage extensions. This allows any leaf certificate (without these extensions) to act as a CA and sign other certificates, which node-forge will accept as valid. Version 1.4.0 patches the issue.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:digitalbazaar:forge:*:*:*:*:*:node.js:*:*
Версия до 1.3.3 (включая)

EPSS

Процентиль: 27%
0.00348
Низкий

7.4 High

CVSS3

9.1 Critical

CVSS3

Дефекты

CWE-295
CWE-295

Связанные уязвимости

CVSS3: 7.4
ubuntu
4 месяца назад

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, `pki.verifyCertificateChain()` does not enforce RFC 5280 basicConstraints requirements when an intermediate certificate lacks both the `basicConstraints` and `keyUsage` extensions. This allows any leaf certificate (without these extensions) to act as a CA and sign other certificates, which node-forge will accept as valid. Version 1.4.0 patches the issue.

CVSS3: 7.4
redhat
4 месяца назад

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, `pki.verifyCertificateChain()` does not enforce RFC 5280 basicConstraints requirements when an intermediate certificate lacks both the `basicConstraints` and `keyUsage` extensions. This allows any leaf certificate (without these extensions) to act as a CA and sign other certificates, which node-forge will accept as valid. Version 1.4.0 patches the issue.

msrc
4 месяца назад

Forge has a basicConstraints bypass in its certificate chain verification (RFC 5280 violation)

CVSS3: 7.4
debian
4 месяца назад

Forge (also called `node-forge`) is a native implementation of Transpo ...

CVSS3: 7.4
github
4 месяца назад

Forge has a basicConstraints bypass in its certificate chain verification (RFC 5280 violation)

EPSS

Процентиль: 27%
0.00348
Низкий

7.4 High

CVSS3

9.1 Critical

CVSS3

Дефекты

CWE-295
CWE-295