{"id":"CVE-2026-4600","title":"Versions of the package jsrsasign before 11.1.1 are vulnerable to Improper Verification of Cryptographic Signature via the DSA domain-parameter validation in KJUR.crypto.DSA.setPublic (and the related DSA/X509 verification flow in src/ds…","summary":"Versions of the package jsrsasign before 11.1.1 are vulnerable to Improper Verification of Cryptographic Signature via the DSA domain-parameter validation in KJUR.crypto.DSA.setPublic (and the related DSA/X509 verification flow in src/ds…","severity":"high","cvss":7.4,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","cwe":["CWE-347"],"vendor":"kjur","product":"jsrsasign","affected":["jsrsasign < 11.1.1"],"patched":["jsrsasign 11.1.1"],"published":"2026-03-23","updated":"2026-09-10","sourceUpdated":"2026-09-10T13:20:22.247","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-4600","references":[{"url":"https://gist.github.com/Kr0emer/bf15ddc097176e951659a24a8e9002a7","label":"report@snyk.io"},{"url":"https://github.com/kjur/jsrsasign/commit/37b4c06b145c7bfd6bc2a6df5d0a12c56b15ef60","label":"report@snyk.io"},{"url":"https://github.com/kjur/jsrsasign/pull/646","label":"report@snyk.io"},{"url":"https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-15812268","label":"report@snyk.io"},{"url":"https://security.snyk.io/vuln/SNYK-JS-JSRSASIGN-15370940","label":"report@snyk.io"},{"url":"https://access.redhat.com/errata/RHSA-2026:19375","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:19409","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:19410","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:6568","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:6720","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:6912","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:6926","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/security/cve/CVE-2026-4600","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2450208","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://gist.github.com/Kr0emer/bf15ddc097176e951659a24a8e9002a7","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4600.json","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-4600"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-4600"}],"tags":["nvd","cve.org","exploit-available","csaf","vex","red-hat"],"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"no","technicalImpact":"total","timestamp":"2026-03-23T14:32:39.569693Z"},"epss":0.00225,"epssPercentile":0.13408,"scores":{"nvd":7.4,"vendor":8.2,"cna":7.4},"ingestedAt":"2026-06-26T16:43:13.617Z","slug":"CVE-2026-4600","body":"## Overview\n\nVersions of the package jsrsasign before 11.1.1 are vulnerable to Improper Verification of Cryptographic Signature via the DSA domain-parameter validation in KJUR.crypto.DSA.setPublic (and the related DSA/X509 verification flow in src/dsa-2.0.js). An attacker can forge DSA signatures or X.509 certificates that X509.verifySignature() accepts by supplying malicious domain parameters such as g=1, y=1, and a fixed r=1, which make the verification equation true for any hash.\n\n## Affected\n\n- `jsrsasign < 11.1.1`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `jsrsasign 11.1.1`\n\n## Vendor advisories\n\n- **RHSA-2026:19409** · Red Hat · fixed in: Migration Toolkit for Virtualization 2.1 · released 2026-05-19 · [advisory](https://access.redhat.com/errata/RHSA-2026:19409)\n- **RHSA-2026:19410** · Red Hat · fixed in: Migration Toolkit for Virtualization 2.9 · released 2026-05-19 · [advisory](https://access.redhat.com/errata/RHSA-2026:19410)\n- **RHSA-2026:6912** · Red Hat · fixed in: Red Hat Quay 3.10 · released 2026-04-07 · [advisory](https://access.redhat.com/errata/RHSA-2026:6912)\n- **RHSA-2026:6720** · Red Hat · fixed in: Red Hat Quay 3.12 · released 2026-04-06 · [advisory](https://access.redhat.com/errata/RHSA-2026:6720)\n- **RHSA-2026:6568** · Red Hat · fixed in: Red Hat Quay 3.15 · released 2026-04-03 · [advisory](https://access.redhat.com/errata/RHSA-2026:6568)\n- **RHSA-2026:19375** · Red Hat · fixed in: Red Hat Quay 3.16 · released 2026-05-19 · [advisory](https://access.redhat.com/errata/RHSA-2026:19375)\n- **RHSA-2026:6926** · Red Hat · fixed in: Red Hat Quay 3.9 · released 2026-04-07 · [advisory](https://access.redhat.com/errata/RHSA-2026:6926)","depth":"midnight","depthScore":53,"depthScoreParts":{"impact":40.7,"likelihood":0,"exploitation":12,"ransomware":0},"changes":[{"seq":201690,"id":"CVE-2026-4600","ts":1789399606181,"field":"exploit_available","old":"false","new":"true"},{"seq":200422,"id":"CVE-2026-4600","ts":1789397219241,"field":"exploit_available","old":"true","new":"false"},{"seq":198346,"id":"CVE-2026-4600","ts":1789391858018,"field":"exploit_available","old":"false","new":"true"},{"seq":196139,"id":"CVE-2026-4600","ts":1789383494374,"field":"exploit_available","old":"true","new":"false"},{"seq":195068,"id":"CVE-2026-4600","ts":1789380375362,"field":"exploit_available","old":"false","new":"true"},{"seq":193855,"id":"CVE-2026-4600","ts":1789378342331,"field":"exploit_available","old":"true","new":"false"},{"seq":192642,"id":"CVE-2026-4600","ts":1789376325484,"field":"exploit_available","old":"false","new":"true"},{"seq":191429,"id":"CVE-2026-4600","ts":1789373251015,"field":"exploit_available","old":"true","new":"false"},{"seq":190214,"id":"CVE-2026-4600","ts":1789369203795,"field":"exploit_available","old":"false","new":"true"},{"seq":189001,"id":"CVE-2026-4600","ts":1789368117528,"field":"exploit_available","old":"true","new":"false"},{"seq":187784,"id":"CVE-2026-4600","ts":1789365064898,"field":"exploit_available","old":"false","new":"true"},{"seq":186571,"id":"CVE-2026-4600","ts":1789363093849,"field":"exploit_available","old":"true","new":"false"},{"seq":185357,"id":"CVE-2026-4600","ts":1789361027756,"field":"exploit_available","old":"false","new":"true"},{"seq":184144,"id":"CVE-2026-4600","ts":1789358018969,"field":"exploit_available","old":"true","new":"false"},{"seq":182395,"id":"CVE-2026-4600","ts":1789354157478,"field":"exploit_available","old":"false","new":"true"},{"seq":181188,"id":"CVE-2026-4600","ts":1789352999183,"field":"exploit_available","old":"true","new":"false"},{"seq":179981,"id":"CVE-2026-4600","ts":1789350082744,"field":"exploit_available","old":"false","new":"true"},{"seq":178774,"id":"CVE-2026-4600","ts":1789347934243,"field":"exploit_available","old":"true","new":"false"},{"seq":177567,"id":"CVE-2026-4600","ts":1789346220150,"field":"exploit_available","old":"false","new":"true"},{"seq":176360,"id":"CVE-2026-4600","ts":1789342853597,"field":"exploit_available","old":"true","new":"false"},{"seq":175814,"id":"CVE-2026-4600","ts":1789338637245,"field":"exploit_available","old":"false","new":"true"},{"seq":175684,"id":"CVE-2026-4600","ts":1789338465014,"field":"exploit_available","old":"true","new":"false"},{"seq":174479,"id":"CVE-2026-4600","ts":1789334663200,"field":"exploit_available","old":"false","new":"true"},{"seq":173274,"id":"CVE-2026-4600","ts":1789333341909,"field":"exploit_available","old":"true","new":"false"},{"seq":172088,"id":"CVE-2026-4600","ts":1789330943238,"field":"exploit_available","old":"false","new":"true"},{"seq":170902,"id":"CVE-2026-4600","ts":1789328461141,"field":"exploit_available","old":"true","new":"false"},{"seq":169697,"id":"CVE-2026-4600","ts":1789326980910,"field":"exploit_available","old":"false","new":"true"},{"seq":168492,"id":"CVE-2026-4600","ts":1789323530832,"field":"exploit_available","old":"true","new":"false"},{"seq":167287,"id":"CVE-2026-4600","ts":1789319423714,"field":"exploit_available","old":"false","new":"true"},{"seq":166082,"id":"CVE-2026-4600","ts":1789318405327,"field":"exploit_available","old":"true","new":"false"},{"seq":164877,"id":"CVE-2026-4600","ts":1789315616336,"field":"exploit_available","old":"false","new":"true"},{"seq":163672,"id":"CVE-2026-4600","ts":1789313343142,"field":"exploit_available","old":"true","new":"false"},{"seq":162467,"id":"CVE-2026-4600","ts":1789311755155,"field":"exploit_available","old":"false","new":"true"},{"seq":161262,"id":"CVE-2026-4600","ts":1789308367668,"field":"exploit_available","old":"true","new":"false"},{"seq":160767,"id":"CVE-2026-4600","ts":1789304309179,"field":"exploit_available","old":"false","new":"true"},{"seq":160314,"id":"CVE-2026-4600","ts":1789303867455,"field":"exploit_available","old":"true","new":"false"},{"seq":159375,"id":"CVE-2026-4600","ts":1789300332285,"field":"exploit_available","old":"false","new":"true"},{"seq":158605,"id":"CVE-2026-4600","ts":1789299358799,"field":"exploit_available","old":"true","new":"false"},{"seq":157569,"id":"CVE-2026-4600","ts":1789296516257,"field":"exploit_available","old":"false","new":"true"},{"seq":156364,"id":"CVE-2026-4600","ts":1789294457029,"field":"exploit_available","old":"true","new":"false"},{"seq":155159,"id":"CVE-2026-4600","ts":1789292721497,"field":"exploit_available","old":"false","new":"true"},{"seq":153954,"id":"CVE-2026-4600","ts":1789289432941,"field":"exploit_available","old":"true","new":"false"},{"seq":152604,"id":"CVE-2026-4600","ts":1789281350211,"field":"exploit_available","old":"false","new":"true"},{"seq":152244,"id":"CVE-2026-4600","ts":1789280966187,"field":"exploit_available","old":"true","new":"false"},{"seq":151205,"id":"CVE-2026-4600","ts":1789277467488,"field":"exploit_available","old":"false","new":"true"},{"seq":150166,"id":"CVE-2026-4600","ts":1789275924022,"field":"exploit_available","old":"true","new":"false"},{"seq":149133,"id":"CVE-2026-4600","ts":1789273633171,"field":"exploit_available","old":"false","new":"true"},{"seq":148100,"id":"CVE-2026-4600","ts":1789270964965,"field":"exploit_available","old":"true","new":"false"},{"seq":146140,"id":"CVE-2026-4600","ts":1789269213603,"field":"exploit_available","old":"false","new":"true"},{"seq":145042,"id":"CVE-2026-4600","ts":1789266181014,"field":"exploit_available","old":"true","new":"false"}]}