forge
digitalbazaar- Product type
- Other
- Catalog vulnerabilities
- 13
Severity across 10 analyzed records
Verify to analyze this security profile
en
Severity across 10 analyzed records
Verify to analyze this security profile
As of 09/19/2026, within CyStack's analyzed data, forge has 1 security vulnerability published in the last 90 days. Of these, 1 is rated High or Critical. None of these vulnerabilities is listed in the CISA KEV catalog. CyStack recommends that organizations and individual users remediate applicable vulnerabilities as soon as possible.
CyStack does not yet have sufficient official-source data to identify the latest version of forge and determine which vulnerabilities affect that version.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan| Vulnerability | Exploitation status | Fix | Published | Severity |
|---|---|---|---|---|
CVE-2026-85393node-forge through 1.4.0 RSA PKCS#1 v1.5 Signature Forgery via Nested DigestAlgorithm Padding | Exploitation statusPublic exploit | FixYes | Published09/03/2026 | SeverityHigh |
CVE-2026-33896Forge has a basicConstraints bypass in its certificate chain verification (RFC 5280 violation) | Exploitation statusPublic exploit | FixNot confirmed | Published03/27/2026 | SeverityHigh |
CVE-2026-33895Forge has signature forgery in Ed25519 due to missing S > L check | Exploitation statusPublic exploit | FixNot confirmed | Published03/27/2026 | SeverityHigh |
CVE-2026-33894Forge has signature forgery in RSA-PKCS due to ASN.1 extra field | Exploitation statusPublic exploit | FixNot confirmed | Published03/27/2026 | SeverityHigh |
CVE-2026-33891Forge has Denial of Service via Infinite Loop in BigInteger.modInverse() with Zero Input | Exploitation statusPublic exploit | FixNot confirmed | Published03/27/2026 | SeverityHigh |
CVE-2025-66030node-forge ASN.1 OID Integer Truncation | Exploitation statusNot known exploited | FixYes | Published11/26/2025 | SeverityMedium |
CVE-2025-66031node-forge ASN.1 Unbounded Recursion | Exploitation statusNot known exploited | FixYes | Published11/26/2025 | SeverityHigh |
CVE-2025-12816 | Exploitation statusNot known exploited | FixNot confirmed | Published11/25/2025 | SeverityHigh |
CVE-2022-24772Improper Verification of Cryptographic Signature in `node-forge` | Exploitation statusNot known exploited | FixNot confirmed | Published03/18/2022 | SeverityHigh |
CVE-2022-24773Improper Verification of Cryptographic Signature in `node-forge` | Exploitation statusNot known exploited | FixNot confirmed | Published03/18/2022 | SeverityMedium |
CVE-2022-24771Improper Verification of Cryptographic Signature in node-forge | Exploitation statusNot known exploited | FixNot confirmed | Published03/18/2022 | SeverityHigh |
CVE-2022-0122Open Redirect in digitalbazaar/forge | Exploitation statusNot confirmed | FixYes | Published01/06/2022 | SeverityMedium |
CVE-2020-7720Prototype Pollution | Exploitation statusNot confirmed | FixNot confirmed | Published09/01/2020 | SeverityCritical |