VulnSea

digitalbazaar has 4 CVEs on record. The busiest recent month was March 2026 with 4. The median CVSS is 7.5 (high).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.5
Publish → KEV
Last 90 days
0 prev 4

Products

  • forge 4
4
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

digitalbazaar vulnerabilities

CVEs affecting digitalbazaar, newest first. Open any entry for full detail, references, and exploit status.

4 CVEsRSS

CVE-2026-33896High· 7.4
5mo ago

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, `pki.verifyCertificateChain()` does not enforce RFC 5280 basicConstraints requirements when an intermediate ce…

Twilightdigitalbazaar · forgeEPSS 0.35%via NVD
CVE-2026-33895High· 7.5
5mo ago

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, Ed25519 signature verification accepts forged non-canonical signatures where the scalar S is not reduced modul…

Twilightdigitalbazaar · forgeEPSS 0.54%via NVD
CVE-2026-33891High· 7.5
5mo ago

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, a Denial of Service (DoS) vulnerability exists in the node-forge library due to an infinite loop in the BigInt…

Twilightdigitalbazaar · forgeEPSS 0.60%via NVD
CVE-2026-33894High· 7.5PoC
5mo ago

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, RSASSA PKCS#1 v1.5 signature verification accepts forged signatures for low public exponent keys (e=3). Attack…

Midnightdigitalbazaar · forgeEPSS 0.47%via NVD
digitalbazaar vulnerabilities (CVEs) · VulnSea