PT-2026-28559 · Forge · Forge

·

CVE-2026-33896

·

Published

2026-03-26

·

Updated

2026-07-02

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Forge versions prior to 1.4.0
Description Forge, a native implementation of Transport Layer Security in JavaScript, has an issue where the pki.verifyCertificateChain() function does not properly enforce RFC 5280 basicConstraints requirements. Specifically, when an intermediate certificate is missing both the basicConstraints and keyUsage extensions, any leaf certificate can act as a Certificate Authority (CA) and sign other certificates, which Forge will incorrectly accept as valid. This bypass allows for the creation of untrusted certificate chains.
Recommendations Update to Forge version 1.4.0 or later.

Exploit

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CLEANSTART-2026-BE61221
CVE-2026-33896
GHSA-2328-F5F3-GJ25
RHSA-2026:24761

Affected Products

Forge