Логотип exploitDog
bind:CVE-2026-4601
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2026-4601

Количество 3

Количество 3

redhat логотип

CVE-2026-4601

17 дней назад

Versions of the package jsrsasign before 11.1.1 are vulnerable to Missing Cryptographic Step via the KJUR.crypto.DSA.signWithMessageHash process in the DSA signing implementation. An attacker can recover the private key by forcing r or s to be zero, so the library emits an invalid signature without retrying, and then solves for x from the resulting signature.

CVSS3: 8.7
EPSS: Низкий
nvd логотип

CVE-2026-4601

17 дней назад

Versions of the package jsrsasign before 11.1.1 are vulnerable to Missing Cryptographic Step via the KJUR.crypto.DSA.signWithMessageHash process in the DSA signing implementation. An attacker can recover the private key by forcing r or s to be zero, so the library emits an invalid signature without retrying, and then solves for x from the resulting signature.

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-w8q8-93cx-6h7r

17 дней назад

jsrsasign: Missing cryptographic validation during DSA signing enables private key extraction

CVSS3: 8.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2026-4601

Versions of the package jsrsasign before 11.1.1 are vulnerable to Missing Cryptographic Step via the KJUR.crypto.DSA.signWithMessageHash process in the DSA signing implementation. An attacker can recover the private key by forcing r or s to be zero, so the library emits an invalid signature without retrying, and then solves for x from the resulting signature.

CVSS3: 8.7
0%
Низкий
17 дней назад
nvd логотип
CVE-2026-4601

Versions of the package jsrsasign before 11.1.1 are vulnerable to Missing Cryptographic Step via the KJUR.crypto.DSA.signWithMessageHash process in the DSA signing implementation. An attacker can recover the private key by forcing r or s to be zero, so the library emits an invalid signature without retrying, and then solves for x from the resulting signature.

CVSS3: 8.7
0%
Низкий
17 дней назад
github логотип
GHSA-w8q8-93cx-6h7r

jsrsasign: Missing cryptographic validation during DSA signing enables private key extraction

CVSS3: 8.7
0%
Низкий
17 дней назад

Уязвимостей на страницу