Skip to main content

Vendor/product archive

kjur / jsrsasign CVEs

Beta · best-effort

12 CVEs tagged to kjur / jsrsasign4 Critical, 7 High, 0 Medium, 1 Low, 0 Unrated.

CVE-2026-4603

Published Mar 23, 2026

Versions of the package jsrsasign before 11.1.1 are vulnerable to Division by zero due to the RSASetPublic/KEYUTIL parsing path in ext/rsa.js and the BigInteger.modPowInt reductio…

CVSS 2.0 · Low
evidence mentions
4
Buzz score
24.1
Vendor/product tagsBeta · best-effort

CVE-2026-4602

Published Mar 23, 2026

Versions of the package jsrsasign before 11.1.1 are vulnerable to Incorrect Conversion between Numeric Types due to handling negative exponents in ext/jsbn2.js. An attacker can fo…

CVSS 7.7 · High
evidence mentions
15
Buzz score
43.7
Vendor/product tagsBeta · best-effort

CVE-2026-4601

Published Mar 23, 2026

Versions of the package jsrsasign before 11.1.1 are vulnerable to Missing Cryptographic Step via the KJUR.crypto.DSA.signWithMessageHash process in the DSA signing implementation.…

CVSS 8.8 · High
evidence mentions
15
Buzz score
43.7
Vendor/product tagsBeta · best-effort

CVE-2026-4600

Published Mar 23, 2026

Versions of the package jsrsasign before 11.1.1 are vulnerable to Improper Verification of Cryptographic Signature via the DSA domain-parameter validation in KJUR.crypto.DSA.setPu…

CVSS 8.1 · High
evidence mentions
15
Buzz score
43.7
Vendor/product tagsBeta · best-effort

CVE-2026-4599

Published Mar 23, 2026

Versions of the package jsrsasign from 7.0.0 and before 11.1.1 are vulnerable to Incomplete Comparison with Missing Factors via the getRandomBigIntegerZeroToMax and getRandomBigIn…

CVSS 9.3 · Critical
evidence mentions
15
Buzz score
43.7
Vendor/product tagsBeta · best-effort

CVE-2026-4598

Published Mar 23, 2026

Versions of the package jsrsasign before 11.1.1 are vulnerable to Infinite loop via the bnModInverse function in ext/jsbn2.js when the BigInteger.modInverse implementation receive…

CVSS 7.7 · High
evidence mentions
15
Buzz score
43.7
Vendor/product tagsBeta · best-effort

CVE-2024-21484

Published Jan 22, 2024

Versions of the package jsrsasign before 11.0.0 are vulnerable to Observable Discrepancy via the RSA PKCS1.5 or RSAOAEP decryption process. An attacker can decrypt ciphertexts by…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-25898

Published Jul 1, 2022

The package jsrsasign before 10.5.25 are vulnerable to Improper Verification of Cryptographic Signature when JWS or JWT signature with non Base64URL encoding special characters or…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2021-30246

Published Apr 7, 2021

In the jsrsasign package through 10.1.13 for Node.js, some invalid RSA PKCS#1 v1.5 signatures are mistakenly recognized to be valid. NOTE: there is no known practical attack.

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-14968

Published Jun 22, 2020

An issue was discovered in the jsrsasign package before 8.0.17 for Node.js. Its RSASSA-PSS (RSA-PSS) implementation does not detect signature manipulation/modification by prependi…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-14967

Published Jun 22, 2020

An issue was discovered in the jsrsasign package before 8.0.18 for Node.js. Its RSA PKCS1 v1.5 decryption implementation does not detect ciphertext modification by prepending '\0'…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-14966

Published Jun 22, 2020

An issue was discovered in the jsrsasign package through 8.0.18 for Node.js. It allows a malleability in ECDSA signatures by not checking overflows in the length of a sequence and…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-12 of 12 CVEsPage 1 of 1