PT-2026-28559 · Forge · Forge

Peaktwilight

·

Published

2026-03-26

·

Updated

2026-04-01

·

CVE-2026-33896

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Forge versions prior to 1.4.0
Description Forge, a native implementation of Transport Layer Security in JavaScript, has an issue where the pki.verifyCertificateChain() function does not properly enforce RFC 5280 basicConstraints requirements. Specifically, when an intermediate certificate is missing both the basicConstraints and keyUsage extensions, any leaf certificate can act as a Certificate Authority (CA) and sign other certificates, which Forge will incorrectly accept as valid. This bypass allows for the creation of untrusted certificate chains.
Recommendations Update to Forge version 1.4.0 or later.

Exploit

Fix

Improper Certificate Validation

Weakness Enumeration

Related Identifiers

CVE-2026-33896
GHSA-2328-F5F3-GJ25

Affected Products

Forge