Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-33896

Опубликовано: 27 мар. 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 7.4

Описание

Forge (also called node-forge) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, pki.verifyCertificateChain() does not enforce RFC 5280 basicConstraints requirements when an intermediate certificate lacks both the basicConstraints and keyUsage extensions. This allows any leaf certificate (without these extensions) to act as a CA and sign other certificates, which node-forge will accept as valid. Version 1.4.0 patches the issue.

РелизСтатусПримечание
devel

DNE

esm-apps/focal

needs-triage

esm-apps/jammy

needs-triage

jammy

needs-triage

noble

DNE

questing

DNE

resolute

DNE

upstream

needs-triage

Показывать по

EPSS

Процентиль: 27%
0.00348
Низкий

7.4 High

CVSS3

Связанные уязвимости

CVSS3: 7.4
redhat
4 месяца назад

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, `pki.verifyCertificateChain()` does not enforce RFC 5280 basicConstraints requirements when an intermediate certificate lacks both the `basicConstraints` and `keyUsage` extensions. This allows any leaf certificate (without these extensions) to act as a CA and sign other certificates, which node-forge will accept as valid. Version 1.4.0 patches the issue.

CVSS3: 7.4
nvd
4 месяца назад

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, `pki.verifyCertificateChain()` does not enforce RFC 5280 basicConstraints requirements when an intermediate certificate lacks both the `basicConstraints` and `keyUsage` extensions. This allows any leaf certificate (without these extensions) to act as a CA and sign other certificates, which node-forge will accept as valid. Version 1.4.0 patches the issue.

msrc
4 месяца назад

Forge has a basicConstraints bypass in its certificate chain verification (RFC 5280 violation)

CVSS3: 7.4
debian
4 месяца назад

Forge (also called `node-forge`) is a native implementation of Transpo ...

CVSS3: 7.4
github
4 месяца назад

Forge has a basicConstraints bypass in its certificate chain verification (RFC 5280 violation)

EPSS

Процентиль: 27%
0.00348
Низкий

7.4 High

CVSS3