CVE-2026-4601 PUBLISHED CVSS 8.699999809265137 HIGH

Versions of the package jsrsasign before 11.1.1 are vulnerable to Missing Cryptographic Step via the KJUR.crypto.DSA.signWithMessageHash process in the DSA signing implementation. An attacker can recover the private key by forcing r or s to be zero, so the library emits an invalid signature without retrying, and then solves for x from the resulting signature.

EPSS 0.02% · 5.0th percentile

Risk Scores

CVSS v3.1
8.699999809265137
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N/E:P
EPSS Score
0.02%
5.0th percentile

Affected Products

VendorProductVersions
npmjsrsasign0
jsrsasign_projectjsrsasign0, 0, 0
n/ajsrsasign0, 0, 0

Timeline

References

Open in Interactive Console →