CVE-2026-33894Disclosure(digitalbazaar / forge)

LOWCVSS 7.5 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, RSASSA PKCS#1 v1.5 signature verification accepts forged signatures for low public exponent keys (e=3). Attackers can forge signatures by stuffing “garbage” bytes within the ASN structure in order to construct a signature that passes verification, enabling Bleichenbacher style forgery. This issue is similar to CVE-2022-24771, but adds bytes in an addition field within the ASN structure, rather than outside of it. Additionally, forge does not validate that signatures include a minimum of 8 bytes of padding as defined by the specification, providing attackers additional space to construct Bleichenbacher forgeries. Version 1.4.0 patches the issue.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20CWE-347

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • forge

Threat summary

  • Public PoC is present in monitored signal
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 4 classified signals
  • Peaked 3d ago at 1 mentions (2026-03-27); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Products
forge

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-03-27: 1Mentions · 2026-03-28: 1Mentions · 2026-07-16: 1Mentions · 2026-08-25: 1PoC Mentioned / Linked · 2026-07-16: 1Technical Details · 2026-03-27: 1Technical Details · 2026-03-28: 1Technical Details · 2026-07-16: 103-2703-2807-1608-25
Signal classification1 categories
Disclosure
4100.0%
Referenced assets3 URLs
Full discourse4 posts
  • DFIR Radar@DFIR_Radar
    Disclosure

    CVE-2026-33894 and CVE-2026-33895 allow RSA-PKCS v1.5 and Ed25519 signature forgery in node-forge v0.1.2 through v1.3.3, with public PoCs already available. #DFIR_Radar https://t.co/RoRjgrLYuO

    Post summary

    The post announces two new CVEs that enable signature forgery in node-forge, noting that public PoCs exist, but it does not provide specific exploit code, active exploitation reports, or patch information.

    10010226
    1.8K followersView on X
  • IntegSec@integ_sec
    Disclosure

    CVE-2026-33894: node-forge RSA Signature Forgery Bug - What It Means for Your Business and How to Respond https://hubs.li/Q04vcQhC0

    Post summary

    The text is the title of an article announcing CVE-2026-33894, a node-forge RSA signature forgery bug, with a focus on business implications and response recommendations.

    0000033
    33 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33894 Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, RSASSA PKCS#1 v1.5 signature verificati… https://www.cve.org/CVERecord?id=CVE-2026-33894

    Post summary

    CVE‑2026‑33894 exposes a vulnerability in node‑forge’s RSASSA PKCS#1 v1.5 signature verification before version 1.4.0, as indicated in the CVE record. No PoC, exploit, patch, or active exploitation is referenced.

    0000099
    56.9K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-33894 - Forge has signature forgery in RSA-PKCS due to ASN.1 extra field Intel Report: https://ift.tt/3Uk2KlD

    Post summary

    The alert announces CVE-2026-33894, describing a signature forgery vulnerability in RSA-PKCS caused by an ASN.1 extra field, with an Intel report linked for further details.

    0000038
    285 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdigitalbazaarforge-node.js-

Explore more