PT-2026-28558 · Unknown · Node-Forge

Corbanvilla

+2

·

Published

2026-03-26

·

Updated

2026-05-18

·

CVE-2026-33895

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Forge (also called node-forge) versions prior to 1.4.0
Description Forge, a native implementation of Transport Layer Security in JavaScript, contains an issue in Ed25519 signature verification. Specifically, the verification process does not properly check if S is greater than L, potentially leading to signature forgery.
Recommendations Update to version 1.4.0 or later.

Exploit

Fix

Improper Verification of Cryptographic Signature

Weakness Enumeration

Related Identifiers

CLEANSTART-2026-BE61221
CVE-2026-33895
GHSA-Q67F-28XG-22RW

Affected Products

Node-Forge