node-forge 1.4.0 及以下版本在验证 RSA PKCS#1 v1.5 签名时,未能正确验证嵌套的 DigestAlgorithm 序列中的元素数量。攻击者可以在 DigestAlgorithm 序列中嵌入垃圾字节,从而利用小指数 RSA 密钥为任意消息伪造有效签名。这是针对 CVE-2026-33894 的不完整修复。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| digitalbazaar | forge | ≤ 1.4.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| digitalbazaar | forge | 0 ~ 1.4.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet