Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 03 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 03 Sep 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | node-forge through 1.4.0 fails to validate element count in nested DigestAlgorithm sequences during RSA PKCS#1 v1.5 signature verification. Attackers can embed garbage bytes inside the DigestAlgorithm sequence to forge valid signatures for arbitrary messages using low-exponent RSA keys. This is an incomplete fix for CVE-2026-33894. | |
| Title | node-forge through 1.4.0 RSA PKCS#1 v1.5 Signature Forgery via Nested DigestAlgorithm Padding | |
| First Time appeared |
Digitalbazaar
Digitalbazaar forge |
|
| Weaknesses | CWE-347 | |
| CPEs | cpe:2.3:a:digitalbazaar:forge:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Digitalbazaar
Digitalbazaar forge |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-03T19:14:06.547Z
Reserved: 2026-09-03T18:10:52.622Z
Link: CVE-2026-85393
Updated: 2026-09-03T19:14:03.413Z
Status : Received
Published: 2026-09-03T19:17:31.103
Modified: 2026-09-03T20:17:28.747
Link: CVE-2026-85393
No data.
OpenCVE Enrichment
No data.