CVE-2026-33895Disclosure(digitalbazaar / forge)

LOWCVSS 7.5 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch digitalbazaar forge systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, Ed25519 signature verification accepts forged non-canonical signatures where the scalar S is not reduced modulo the group order (`S >= L`). A valid signature and its `S + L` variant both verify in forge, while Node.js `crypto.verify` (OpenSSL-backed) rejects the `S + L` variant, as defined by the specification. This class of signature malleability has been exploited in practice to bypass authentication and authorization logic (see CVE-2026-25793, CVE-2022-35961). Applications relying on signature uniqueness (i.e., dedup by signature bytes, replay tracking, signed-object canonicalization checks) may be bypassed. Version 1.4.0 patches the issue.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-347

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • forge

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 3d ago at 1 mentions (2026-03-27); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Products
forge

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-03-27: 1Mentions · 2026-03-28: 1Mentions · 2026-07-16: 1Mentions · 2026-08-25: 1PoC Mentioned / Linked · 2026-07-16: 1Patch / Workaround · 2026-08-25: 1Technical Details · 2026-03-27: 1Technical Details · 2026-03-28: 1Technical Details · 2026-07-16: 1Technical Details · 2026-08-25: 103-2703-2807-1608-25
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-271
Disclosure1
2026-03-281
Disclosure1
2026-07-161
Disclosure1
2026-08-251
Patch1
Full discourse4 posts
  • DFIR Radar@DFIR_Radar
    Disclosure

    CVE-2026-33894 and CVE-2026-33895 allow RSA-PKCS v1.5 and Ed25519 signature forgery in node-forge v0.1.2 through v1.3.3, with public PoCs already available. #DFIR_Radar https://t.co/RoRjgrLYuO

    Post summary

    The tweet announces that CVE‑2026‑33894 and CVE‑2026‑33895 allow signature forgery in node‑forge and that public PoCs exist; no exploitation or patch info is mentioned.

    10010226
    1.8K followersView on X
  • IntegSec@integ_sec
    Patch

    CVE-2026-33895: node-forge Signature Verification Bug - What It Means for Your Business and How to Respond https://hubs.li/Q04vggT_0

    Post summary

    The article highlights the node‑forge Signature Verification bug (CVE‑2026‑33895), explaining its business impact and outlining mitigation steps, including suggested patches or workarounds.

    0000033
    33 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33895 Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, Ed25519 signature verification accepts … https://www.cve.org/CVERecord?id=CVE-2026-33895

    Post summary

    CVE-2026-33895 affects the node‑forge library (Ed25519 signature verification flaw) before version 1.4.0.

    00000107
    56.9K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-33895 - Forge has signature forgery in Ed25519 due to missing S > L check Intel Report: https://ift.tt/HTq2j43

    Post summary

    The text announces the discovery of CVE-2026-33895, detailing a signature forgery flaw in Forge's Ed25519 implementation, without presenting patches, exploits, or evidence of active exploitation.

    0000029
    285 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdigitalbazaarforge-node.js-

Explore more