Логотип exploitDog
bind:CVE-2026-4599
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2026-4599

Количество 3

Количество 3

redhat логотип

CVE-2026-4599

17 дней назад

Versions of the package jsrsasign from 7.0.0 and before 11.1.1 are vulnerable to Incomplete Comparison with Missing Factors via the getRandomBigIntegerZeroToMax and getRandomBigIntegerMinToMax functions in src/crypto-1.1.js; an attacker can recover the private key by exploiting the incorrect compareTo checks that accept out-of-range candidates and thus bias DSA nonces during signature generation.

CVSS3: 9.1
EPSS: Низкий
nvd логотип

CVE-2026-4599

17 дней назад

Versions of the package jsrsasign from 7.0.0 and before 11.1.1 are vulnerable to Incomplete Comparison with Missing Factors via the getRandomBigIntegerZeroToMax and getRandomBigIntegerMinToMax functions in src/crypto-1.1.js; an attacker can recover the private key by exploiting the incorrect compareTo checks that accept out-of-range candidates and thus bias DSA nonces during signature generation.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-5jx8-q4cp-rhh6

17 дней назад

jsrsasign: Incomplete Comparison Allows DSA Private Key Recovery via Biased Nonce Generation

CVSS3: 9.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2026-4599

Versions of the package jsrsasign from 7.0.0 and before 11.1.1 are vulnerable to Incomplete Comparison with Missing Factors via the getRandomBigIntegerZeroToMax and getRandomBigIntegerMinToMax functions in src/crypto-1.1.js; an attacker can recover the private key by exploiting the incorrect compareTo checks that accept out-of-range candidates and thus bias DSA nonces during signature generation.

CVSS3: 9.1
0%
Низкий
17 дней назад
nvd логотип
CVE-2026-4599

Versions of the package jsrsasign from 7.0.0 and before 11.1.1 are vulnerable to Incomplete Comparison with Missing Factors via the getRandomBigIntegerZeroToMax and getRandomBigIntegerMinToMax functions in src/crypto-1.1.js; an attacker can recover the private key by exploiting the incorrect compareTo checks that accept out-of-range candidates and thus bias DSA nonces during signature generation.

CVSS3: 9.1
0%
Низкий
17 дней назад
github логотип
GHSA-5jx8-q4cp-rhh6

jsrsasign: Incomplete Comparison Allows DSA Private Key Recovery via Biased Nonce Generation

CVSS3: 9.1
0%
Низкий
17 дней назад

Уязвимостей на страницу