Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-85393

Опубликовано: 03 сент. 2026
Источник: redhat
CVSS3: 7.5

Описание

node-forge through 1.4.0 fails to validate element count in nested DigestAlgorithm sequences during RSA PKCS#1 v1.5 signature verification. Attackers can embed garbage bytes inside the DigestAlgorithm sequence to forge valid signatures for arbitrary messages using low-exponent RSA keys. This is an incomplete fix for CVE-2026-33894.

A flaw was found in node-forge. This vulnerability allows a remote attacker to forge valid RSA PKCS#1 v1.5 signatures for arbitrary messages. The flaw occurs because the software fails to properly validate the element count in nested DigestAlgorithm sequences during signature verification. By embedding specially crafted data, an attacker can bypass signature validation, leading to potential integrity compromise.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Gatekeeper 3gatekeeper/gatekeeper-rhel9Affected
Node HealthCheck Operatorworkload-availability/node-healthcheck-must-gather-rhel9Affected
Node HealthCheck Operatorworkload-availability/node-healthcheck-operator-bundleAffected
Node HealthCheck Operatorworkload-availability/node-healthcheck-rhel9-operatorAffected
Node HealthCheck Operatorworkload-availability/node-remediation-console-rhel8Affected
OpenShift Pipelinesopenshift-pipelines/pipelines-hub-ui-rhel8Affected
OpenShift Pipelinesopenshift-pipelines/pipelines-hub-ui-rhel9Affected
OpenShift Service Mesh 3openshift-service-mesh/kiali-operator-bundleNot affected
OpenShift Service Mesh 3openshift-service-mesh/kiali-rhel9-operatorNot affected
Red Hat 3scale API Management Platform 23scale-amp2/system-rhel8Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-1284
https://bugzilla.redhat.com/show_bug.cgi?id=2528186node-forge: node-forge: Signature forgery vulnerability in RSA PKCS#1 v1.5 verification

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
12 дней назад

node-forge through 1.4.0 fails to validate element count in nested DigestAlgorithm sequences during RSA PKCS#1 v1.5 signature verification. Attackers can embed garbage bytes inside the DigestAlgorithm sequence to forge valid signatures for arbitrary messages using low-exponent RSA keys. This is an incomplete fix for CVE-2026-33894.

CVSS3: 7.5
nvd
13 дней назад

node-forge through 1.4.0 fails to validate element count in nested DigestAlgorithm sequences during RSA PKCS#1 v1.5 signature verification. Attackers can embed garbage bytes inside the DigestAlgorithm sequence to forge valid signatures for arbitrary messages using low-exponent RSA keys. This is an incomplete fix for CVE-2026-33894.

msrc
9 дней назад

node-forge through 1.4.0 RSA PKCS#1 v1.5 Signature Forgery via Nested DigestAlgorithm Padding

CVSS3: 7.5
debian
13 дней назад

node-forge through 1.4.0 fails to validate element count in nested Dig ...

CVSS3: 7.5
github
12 дней назад

node-forge through 1.4.0 fails to validate element count in nested DigestAlgorithm sequences during RSA PKCS#1 v1.5 signature verification. Attackers can embed garbage bytes inside the DigestAlgorithm sequence to forge valid signatures for arbitrary messages using low-exponent RSA keys. This is an incomplete fix for CVE-2026-33894.

7.5 High

CVSS3