VDB
CVE-2026-4601
CVE-2026-4601
PUBLISHED
CVSS 8.699999809265137 HIGH
Versions of the package jsrsasign before 11.1.1 are vulnerable to Missing Cryptographic Step via the KJUR.crypto.DSA.signWithMessageHash process in the DSA signing implementation. An attacker can recover the private key by forcing r or s to be zero, so the library emits an invalid signature without retrying, and then solves for x from the resulting signature.
EPSS 0.02% · 6.9th percentile
Risk Scores
CVSS 3.1
8.699999809265137
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N/E:P
EPSS Score
0.02%
6.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| npm | jsrsasign | 0 |
| jsrsasign_project | jsrsasign | 0, 0, 0 |
| n/a | jsrsasign | 0, 0, 0 |
Exploit Intelligence
- https://gist.github.com/Kr0emer/93789fe6efe5519db9692d4ad1dad586 (nist-nvd)
- CIRCL seen: CVE-2026-4601 (circl-sighting)
- CIRCL seen: CVE-2026-4601 (circl-sighting)
- CIRCL seen: CVE-2026-4601 (circl-sighting)
- https://security.snyk.io/vuln/SNYK-JS-JSRSASIGN-15370941 (circl)
- https://github.com/kjur/jsrsasign/pull/645 (circl)
- https://github.com/kjur/jsrsasign/commit/0710e392ec35de697ce11e4219c988ba2b5fe0eb (circl)
- GitHub Gist: 93789fe6efe5519db9692d4ad1dad586 (github)
- GitHub Gist: 93789fe6efe5519db9692d4ad1dad586 (github)
- GitHub Gist: 93789fe6efe5519db9692d4ad1dad586 (github)
Timeline
- Mar 23, 2026 CVE Published
- Mar 23, 2026 EPSS Score
- Mar 23, 2026 PoC Published
- Mar 23, 2026 PoC Published
- Mar 23, 2026 PoC Published
- Mar 24, 2026 EPSS Score
- Mar 25, 2026 EPSS Score
- Mar 25, 2026 Coalition ESS Score
- Mar 26, 2026 EPSS Score
- Mar 26, 2026 Coalition ESS Score
- Mar 27, 2026 Coalition ESS Score
- Mar 29, 2026 CVE Updated
References
- https://security.snyk.io/vuln/SNYK-JS-JSRSASIGN-15370941 url
- https://gist.github.com/Kr0emer/93789fe6efe5519db9692d4ad1dad586 url
- https://github.com/kjur/jsrsasign/pull/645 url
- https://github.com/kjur/jsrsasign/commit/0710e392ec35de697ce11e4219c988ba2b5fe0eb url
- https://nvd.nist.gov/vuln/detail/CVE-2026-4601 advisory
- https://github.com/kjur/jsrsasign package