PT-2026-27055 · Jsrsasign · Jsrsasign

·

CVE-2026-4599

·

Published

2026-03-23

·

Updated

2026-07-01

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions jsrsasign versions 7.0.0 through 11.1.1
Description An issue exists involving incomplete comparison with missing factors within the getRandomBigIntegerZeroToMax() and getRandomBigIntegerMinToMax() functions located in src/crypto-1.1.js. An attacker can recover the private key by exploiting incorrect compareTo checks that accept out-of-range candidates, which biases DSA nonces during the signature generation process.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-4599
GHSA-5JX8-Q4CP-RHH6

Affected Products

Jsrsasign