Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 6

Количество 6

ubuntu логотип

CVE-2026-33891

4 месяца назад

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, a Denial of Service (DoS) vulnerability exists in the node-forge library due to an infinite loop in the BigInteger.modInverse() function (inherited from the bundled jsbn library). When modInverse() is called with a zero value as input, the internal Extended Euclidean Algorithm enters an unreachable exit condition, causing the process to hang indefinitely and consume 100% CPU. Version 1.4.0 patches the issue.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2026-33891

4 месяца назад

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, a Denial of Service (DoS) vulnerability exists in the node-forge library due to an infinite loop in the BigInteger.modInverse() function (inherited from the bundled jsbn library). When modInverse() is called with a zero value as input, the internal Extended Euclidean Algorithm enters an unreachable exit condition, causing the process to hang indefinitely and consume 100% CPU. Version 1.4.0 patches the issue.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-33891

4 месяца назад

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, a Denial of Service (DoS) vulnerability exists in the node-forge library due to an infinite loop in the BigInteger.modInverse() function (inherited from the bundled jsbn library). When modInverse() is called with a zero value as input, the internal Extended Euclidean Algorithm enters an unreachable exit condition, causing the process to hang indefinitely and consume 100% CPU. Version 1.4.0 patches the issue.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2026-33891

4 месяца назад

Forge has Denial of Service via Infinite Loop in BigInteger.modInverse() with Zero Input

EPSS: Низкий
debian логотип

CVE-2026-33891

4 месяца назад

Forge (also called `node-forge`) is a native implementation of Transpo ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-5m6q-g25r-mvwx

4 месяца назад

Forge has Denial of Service via Infinite Loop in BigInteger.modInverse() with Zero Input

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-33891

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, a Denial of Service (DoS) vulnerability exists in the node-forge library due to an infinite loop in the BigInteger.modInverse() function (inherited from the bundled jsbn library). When modInverse() is called with a zero value as input, the internal Extended Euclidean Algorithm enters an unreachable exit condition, causing the process to hang indefinitely and consume 100% CPU. Version 1.4.0 patches the issue.

CVSS3: 7.5
1%
Низкий
4 месяца назад
redhat логотип
CVE-2026-33891

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, a Denial of Service (DoS) vulnerability exists in the node-forge library due to an infinite loop in the BigInteger.modInverse() function (inherited from the bundled jsbn library). When modInverse() is called with a zero value as input, the internal Extended Euclidean Algorithm enters an unreachable exit condition, causing the process to hang indefinitely and consume 100% CPU. Version 1.4.0 patches the issue.

CVSS3: 7.5
1%
Низкий
4 месяца назад
nvd логотип
CVE-2026-33891

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, a Denial of Service (DoS) vulnerability exists in the node-forge library due to an infinite loop in the BigInteger.modInverse() function (inherited from the bundled jsbn library). When modInverse() is called with a zero value as input, the internal Extended Euclidean Algorithm enters an unreachable exit condition, causing the process to hang indefinitely and consume 100% CPU. Version 1.4.0 patches the issue.

CVSS3: 7.5
1%
Низкий
4 месяца назад
msrc логотип
CVE-2026-33891

Forge has Denial of Service via Infinite Loop in BigInteger.modInverse() with Zero Input

1%
Низкий
4 месяца назад
debian логотип
CVE-2026-33891

Forge (also called `node-forge`) is a native implementation of Transpo ...

CVSS3: 7.5
1%
Низкий
4 месяца назад
github логотип
GHSA-5m6q-g25r-mvwx

Forge has Denial of Service via Infinite Loop in BigInteger.modInverse() with Zero Input

CVSS3: 7.5
1%
Низкий
4 месяца назад

Уязвимостей на страницу