digitalbazaar
- Total products in the ecosystem
- 3
- Total vulnerabilities (90 days)
- 1
en
Verify to analyze this security profile
As of 09/19/2026, digitalbazaar recorded 1 security vulnerabilities in the last 90 days across 1 products, including 1 rated High or above and 0 known exploited vulnerabilities (KEV) that should be prioritized for immediate remediation.
Over the last 90 days, forge had the most security vulnerabilities in the digitalbazaar ecosystem, with 1 vulnerabilities—approximately 100% of the provider's total vulnerabilities during this period.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan| Vulnerability | Exploitation status | Fix | Affected product | Published | Severity |
|---|---|---|---|---|---|
CVE-2026-85393node-forge through 1.4.0 RSA PKCS#1 v1.5 Signature Forgery via Nested DigestAlgorithm Padding | Exploitation statusPublic exploit | FixYes | Affected productforge | Published09/03/2026 | SeverityHigh |
CVE-2026-33896Forge has a basicConstraints bypass in its certificate chain verification (RFC 5280 violation) | Exploitation statusPublic exploit | FixNot confirmed | Affected productforge | Published03/27/2026 | SeverityHigh |
CVE-2026-33895Forge has signature forgery in Ed25519 due to missing S > L check | Exploitation statusPublic exploit | FixNot confirmed | Affected productforge | Published03/27/2026 | SeverityHigh |
CVE-2026-33894Forge has signature forgery in RSA-PKCS due to ASN.1 extra field | Exploitation statusPublic exploit | FixNot confirmed | Affected productforge | Published03/27/2026 | SeverityHigh |
CVE-2026-33891Forge has Denial of Service via Infinite Loop in BigInteger.modInverse() with Zero Input | Exploitation statusPublic exploit | FixNot confirmed | Affected productforge | Published03/27/2026 | SeverityHigh |
CVE-2025-66030node-forge ASN.1 OID Integer Truncation | Exploitation statusNot known exploited | FixYes | Affected productforge | Published11/26/2025 | SeverityMedium |
CVE-2025-66031node-forge ASN.1 Unbounded Recursion | Exploitation statusNot known exploited | FixYes | Affected productforge | Published11/26/2025 | SeverityHigh |
CVE-2025-12816 | Exploitation statusNot known exploited | FixNot confirmed | Affected productnode-forge | Published11/25/2025 | SeverityHigh |
CVE-2024-31995zcap has incomplete expiration checks in capability chains. | Exploitation statusNot known exploited | FixNot confirmed | Affected productzcap | Published04/10/2024 | SeverityMedium |
CVE-2022-24772Improper Verification of Cryptographic Signature in `node-forge` | Exploitation statusNot known exploited | FixNot confirmed | Affected productforge | Published03/18/2022 | SeverityHigh |
CVE-2022-24773Improper Verification of Cryptographic Signature in `node-forge` | Exploitation statusNot known exploited | FixNot confirmed | Affected productforge | Published03/18/2022 | SeverityMedium |
CVE-2022-24771Improper Verification of Cryptographic Signature in node-forge | Exploitation statusNot known exploited | FixNot confirmed | Affected productforge | Published03/18/2022 | SeverityHigh |
CVE-2022-0122Open Redirect in digitalbazaar/forge | Exploitation statusNot confirmed | FixYes | Affected productdigitalbazaar/forge | Published01/06/2022 | SeverityMedium |
CVE-2020-7720Prototype Pollution | Exploitation statusNot confirmed | FixNot confirmed | Affected productnode-forge | Published09/01/2020 | SeverityCritical |