PT-2026-27056 · Jsrsasign · Jsrsasign
Kr0Emer
·
Published
2026-03-23
·
Updated
2026-03-28
·
CVE-2026-4600
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
jsrsasign versions prior to 11.1.1
Description
The software is susceptible to an issue involving improper verification of cryptographic signatures. This occurs due to inadequate validation of domain parameters within the DSA (Digital Signature Algorithm) implementation, specifically in the
KJUR.crypto.DSA.setPublic function and related X509 verification processes in src/dsa-2.0.js. An attacker can exploit this by providing malicious domain parameters, such as setting g and y to 1 and r to 1, which allows the forging of DSA signatures or X.509 certificates that the X509.verifySignature() function will incorrectly accept.Recommendations
Update jsrsasign to version 11.1.1 or later.
Exploit
Fix
Improper Verification of Cryptographic Signature
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jsrsasign