Digital Bazaar Forge是美国Digital Bazaar公司的一个 Tls 在 Javascript 中的本机实现以及用于编写基于加密和网络密集型 Web 应用程序的开源工具。 Digital Bazaar Forge 1.4.0之前版本存在数据伪造问题漏洞,该漏洞源于RSASSA PKCS#1 v1.5签名验证接受低公共指数密钥的伪造签名,可能导致Bleichenbacher风格伪造攻击。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| digitalbazaar | forge | < 1.4.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| digitalbazaar | forge | < 1.4.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-33891 | 7.5 HIGH | Forge has Denial of Service via Infinite Loop in BigInteger.modInverse() with Zero Input |
| CVE-2026-33895 | 7.5 HIGH | Forge has signature forgery in Ed25519 due to missing S > L check |
| CVE-2026-33896 | 7.4 HIGH | Forge has a basicConstraints bypass in its certificate chain verification (RFC 5280 violat |
No comments yet