Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-33896

Опубликовано: 27 мар. 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 7.4

Описание

Forge (also called node-forge) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, pki.verifyCertificateChain() does not enforce RFC 5280 basicConstraints requirements when an intermediate certificate lacks both the basicConstraints and keyUsage extensions. This allows any leaf certificate (without these extensions) to act as a CA and sign other certificates, which node-forge will accept as valid. Version 1.4.0 patches the issue.

РелизСтатусПримечание
devel

DNE

esm-apps/focal

needs-triage

esm-apps/jammy

needs-triage

jammy

needs-triage

noble

DNE

questing

DNE

upstream

needs-triage

Показывать по

EPSS

Процентиль: 6%
0.00022
Низкий

7.4 High

CVSS3

Связанные уязвимости

CVSS3: 7.4
redhat
16 дней назад

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, `pki.verifyCertificateChain()` does not enforce RFC 5280 basicConstraints requirements when an intermediate certificate lacks both the `basicConstraints` and `keyUsage` extensions. This allows any leaf certificate (without these extensions) to act as a CA and sign other certificates, which node-forge will accept as valid. Version 1.4.0 patches the issue.

CVSS3: 7.4
nvd
16 дней назад

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, `pki.verifyCertificateChain()` does not enforce RFC 5280 basicConstraints requirements when an intermediate certificate lacks both the `basicConstraints` and `keyUsage` extensions. This allows any leaf certificate (without these extensions) to act as a CA and sign other certificates, which node-forge will accept as valid. Version 1.4.0 patches the issue.

msrc
11 дней назад

Forge has a basicConstraints bypass in its certificate chain verification (RFC 5280 violation)

CVSS3: 7.4
debian
16 дней назад

Forge (also called `node-forge`) is a native implementation of Transpo ...

CVSS3: 7.4
github
17 дней назад

Forge has a basicConstraints bypass in its certificate chain verification (RFC 5280 violation)

EPSS

Процентиль: 6%
0.00022
Низкий

7.4 High

CVSS3