PT-2026-28559 · Forge · Forge
Peaktwilight
·
Publicado
2026-03-26
·
Atualizado
2026-05-18
·
CVE-2026-33896
CVSS v3.1
9.1
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Forge versions prior to 1.4.0
Description
Forge, a native implementation of Transport Layer Security in JavaScript, has an issue where the
pki.verifyCertificateChain() function does not properly enforce RFC 5280 basicConstraints requirements. Specifically, when an intermediate certificate is missing both the basicConstraints and keyUsage extensions, any leaf certificate can act as a Certificate Authority (CA) and sign other certificates, which Forge will incorrectly accept as valid. This bypass allows for the creation of untrusted certificate chains.Recommendations
Update to Forge version 1.4.0 or later.
Exploit
Correção
Improper Certificate Validation
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Forge