PT-2026-27055 · Jsrsasign · Jsrsasign
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
jsrsasign versions 7.0.0 through 11.1.1
Description
An issue exists involving incomplete comparison with missing factors within the
getRandomBigIntegerZeroToMax() and getRandomBigIntegerMinToMax() functions located in src/crypto-1.1.js. An attacker can recover the private key by exploiting incorrect compareTo checks that accept out-of-range candidates, which biases DSA nonces during the signature generation process.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jsrsasign