VulnSea

forge vulnerabilities

CVEs whose affected-version data names the forge package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

4 CVEsRSS

CVE-2026-33896High· 7.4
5mo ago

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, `pki.verifyCertificateChain()` does not enforce RFC 5280 basicConstraints requirements when an intermediate ce…

Twilightdigitalbazaar · forgeEPSS 0.35%via NVD
CVE-2026-33895High· 7.5
5mo ago

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, Ed25519 signature verification accepts forged non-canonical signatures where the scalar S is not reduced modul…

Twilightdigitalbazaar · forgeEPSS 0.54%via NVD
CVE-2026-33891High· 7.5
5mo ago

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, a Denial of Service (DoS) vulnerability exists in the node-forge library due to an infinite loop in the BigInt…

Twilightdigitalbazaar · forgeEPSS 0.60%via NVD
CVE-2026-33894High· 7.5PoC
5mo ago

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, RSASSA PKCS#1 v1.5 signature verification accepts forged signatures for low public exponent keys (e=3). Attack…

Midnightdigitalbazaar · forgeEPSS 0.47%via NVD
forge vulnerabilities (CVEs) · VulnSea