PT-2026-28559 · Forge · Forge

Peaktwilight

·

Publicado

2026-03-26

·

Atualizado

2026-05-18

·

CVE-2026-33896

CVSS v3.1

9.1

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Forge versions prior to 1.4.0
Description Forge, a native implementation of Transport Layer Security in JavaScript, has an issue where the pki.verifyCertificateChain() function does not properly enforce RFC 5280 basicConstraints requirements. Specifically, when an intermediate certificate is missing both the basicConstraints and keyUsage extensions, any leaf certificate can act as a Certificate Authority (CA) and sign other certificates, which Forge will incorrectly accept as valid. This bypass allows for the creation of untrusted certificate chains.
Recommendations Update to Forge version 1.4.0 or later.

Exploit

Correção

Improper Certificate Validation

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CLEANSTART-2026-BE61221
CVE-2026-33896
GHSA-2328-F5F3-GJ25

Produtos afetados

Forge