Skip to content
COOEY

EXPOSURES › CVE-2026-4601

CVE-2026-4601

HIGH
DETAIL
SourceNVD · cve Published2026-03-23 CVSS8.7 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-4601 ↗
SHAME 25/100

Versions of the package jsrsasign before 11.1.1 are vulnerable to Missing Cryptographic Step via the KJUR.crypto.DSA.signWithMessageHash process in the DSA signing implementation. An attacker can recover the private key by forcing r or s to be zero, so the library emits an invali

▸ RECOMMENDED ACTION  Patch the affected products and confirm your instances are covered.

DESCRIPTION

Versions of the package jsrsasign before 11.1.1 are vulnerable to Missing Cryptographic Step via the KJUR.crypto.DSA.signWithMessageHash process in the DSA signing implementation. An attacker can recover the private key by forcing r or s to be zero, so the library emits an invalid signature without retrying, and then solves for x from the resulting signature.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.