node-forge RSA PKCS#1 v1.5 signature verification accepts extra nested DigestAlgorithm elements
High severity
GitHub Reviewed
Published
Sep 3, 2026
to the GitHub Advisory Database
•
Updated Oct 1, 2026
Description
Published by the National Vulnerability Database
Sep 3, 2026
Published to the GitHub Advisory Database
Sep 3, 2026
Reviewed
Oct 1, 2026
Last updated
Oct 1, 2026
node-forge through 1.4.0 fails to validate element count in nested DigestAlgorithm sequences during RSA PKCS#1 v1.5 signature verification. Attackers can embed garbage bytes inside the DigestAlgorithm sequence to forge valid signatures for arbitrary messages using low-exponent RSA keys. This is an incomplete fix for CVE-2026-33894.
References