Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-4599

Опубликовано: 23 мар. 2026
Источник: nvd
CVSS3: 9.1
EPSS Низкий

Описание

Versions of the package jsrsasign from 7.0.0 and before 11.1.1 are vulnerable to Incomplete Comparison with Missing Factors via the getRandomBigIntegerZeroToMax and getRandomBigIntegerMinToMax functions in src/crypto-1.1.js; an attacker can recover the private key by exploiting the incorrect compareTo checks that accept out-of-range candidates and thus bias DSA nonces during signature generation.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:jsrsasign_project:jsrsasign:*:*:*:*:*:node.js:*:*
Версия от 7.0.0 (включая) до 11.1.1 (исключая)

EPSS

Процентиль: 11%
0.00037
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-1023

Связанные уязвимости

CVSS3: 9.1
redhat
17 дней назад

Versions of the package jsrsasign from 7.0.0 and before 11.1.1 are vulnerable to Incomplete Comparison with Missing Factors via the getRandomBigIntegerZeroToMax and getRandomBigIntegerMinToMax functions in src/crypto-1.1.js; an attacker can recover the private key by exploiting the incorrect compareTo checks that accept out-of-range candidates and thus bias DSA nonces during signature generation.

CVSS3: 9.1
github
17 дней назад

jsrsasign: Incomplete Comparison Allows DSA Private Key Recovery via Biased Nonce Generation

EPSS

Процентиль: 11%
0.00037
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-1023