VDB

CVE-2026-4601

CVE-2026-4601 PUBLISHED CVSS 8.699999809265137 HIGH

Versions of the package jsrsasign before 11.1.1 are vulnerable to Missing Cryptographic Step via the KJUR.crypto.DSA.signWithMessageHash process in the DSA signing implementation. An attacker can recover the private key by forcing r or s to be zero, so the library emits an invalid signature without retrying, and then solves for x from the resulting signature.

EPSS 0.02% · 6.9th percentile

Risk Scores

CVSS 3.1
8.699999809265137
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N/E:P
EPSS Score
0.02%
6.9th percentile

Affected Products

VendorProductVersions
npmjsrsasign0
jsrsasign_projectjsrsasign0, 0, 0
n/ajsrsasign0, 0, 0

Timeline

  • Mar 23, 2026 CVE Published
  • Mar 23, 2026 EPSS Score
  • Mar 23, 2026 PoC Published
  • Mar 23, 2026 PoC Published
  • Mar 23, 2026 PoC Published
  • Mar 24, 2026 EPSS Score
  • Mar 25, 2026 EPSS Score
  • Mar 25, 2026 Coalition ESS Score
  • Mar 26, 2026 EPSS Score
  • Mar 26, 2026 Coalition ESS Score
  • Mar 27, 2026 Coalition ESS Score
  • Mar 29, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›