HIGH🇬🇧 English

CVE-2026-4601

CVSS 8.8v4.0pub. 2026-03-23upd. 2026-08-17

Versions of the package jsrsasign before 11.1.1 are vulnerable to Missing Cryptographic Step via the KJUR.crypto.DSA.signWithMessageHash process in the DSA signing implementation. An attacker can recover the private key by forcing r or s to be zero, so the library emits an invalid signature without retrying, and then solves for x from the resulting signature.

oryginał EN
CVSS Vector
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:H/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Kjur Jsrsasign

    APP
    Kjur
    < 11.1.1
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Referencje

Powiązane podatności

CVE-2026-4599CRITICAL9.3PL ✓ten sam produkt

Odtworzenie klucza prywatnego DSA przez błąd porównań w jsrsasign

CVE-2021-30246CRITICAL9.1PL ✓ten sam produkt

Błędna weryfikacja podpisów RSA PKCS#1 v1.5 w jsrsasign

CVE-2020-14968CRITICAL9.8PL ✓ten sam produkt

Błąd weryfikacji podpisu RSA-PSS w bibliotece jsrsasign (Node.js)

CVE-2020-14967CRITICAL9.8PL ✓ten sam produkt

Błąd weryfikacji szyfrogramu RSA PKCS1 v1.5 w bibliotece jsrsasign

CVE-2026-4598HIGH7.7ten sam produkt

Versions of the package jsrsasign before 11.1.1 are vulnerable to Infinite loop via the bnModInverse function ...