PT-2026-27057 · Jsrsasign · Jsrsasign
Kr0Emer
·
Publicado
2026-03-23
·
Atualizado
2026-03-28
·
CVE-2026-4601
CVSS v3.1
9.1
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
jsrsasign versions prior to 11.1.1
Description
The jsrsasign package, versions prior to 11.1.1, contains a flaw in the DSA signing implementation, specifically within the
KJUR.crypto.DSA.signWithMessageHash process. This issue allows an attacker to potentially recover the private key by manipulating the signing process to force r or s to be zero. The library then emits an invalid signature without retrying, enabling the attacker to solve for x and thus recover the private key.Recommendations
Update jsrsasign to version 11.1.1 or later.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Jsrsasign