CVE-2026-4599Disclosure(kjur / jsrsasign)

LOWCVSS 9.3 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch kjur jsrsasign systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Versions of the package jsrsasign from 7.0.0 and before 11.1.1 are vulnerable to Incomplete Comparison with Missing Factors via the getRandomBigIntegerZeroToMax and getRandomBigIntegerMinToMax functions in src/crypto-1.1.js; an attacker can recover the private key by exploiting the incorrect compareTo checks that accept out-of-range candidates and thus bias DSA nonces during signature generation.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1023CWE-338

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • jsrsasign

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 6 classified signals
  • Peaked 1d ago at 5 mentions (2026-03-23); latest day: 1
  • 6 total mentions across 2 days

Affected systems

Vendors
Products
jsrsasign

Deep dive

Activity timeline6 mentions / 2d
01345Mentions · 2026-03-23: 5Mentions · 2026-03-31: 1Patch / Workaround · 2026-03-31: 1Technical Details · 2026-03-23: 5Technical Details · 2026-03-31: 103-2303-31
Signal classification1 categories
Disclosure
6100.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-235
Disclosure5
2026-03-311
Disclosure1
Full discourse6 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-4599 Cryptographic Vulnerability in jsrsasign Leading to Private Key Recovery https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4599

    Post summary

    A cryptographic vulnerability (CVE-2026-4599) in jsrsasign that could allow private key recovery has been disclosed via Vulmon, with no PoC, exploit, or patch details provided.

    0000141
    4.0K followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    Critical vulnerability (CVE-2026-4599) in `jsrsasign` allows DSA private key recovery. Review cryptographic practices and await patch. #jsrsasign #cryptography #infosec https://www.pulsepatch.io/posts/cve-2026-4599-jsrsasign-dsa-private-key-recovery

    Post summary

    A critical CVE-2026-4599 vulnerability in jsrsasign that permits DSA private key recovery has been disclosed, urging users to review cryptographic practices and await an official patch.

    0000015
    6 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-4599 📊 Severity: 9.1 🚨 Risk Level: Critical 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-4599 #CVE-2026-4599 #CVE #Critical  #CyberSecurity #InfoSec https://t.co/UiIZUnSwlR

    Post summary

    The tweet announces a new CVE-2026-4599 with a severity score of 9.1, providing basic risk information but no deeper technical or mitigation details.

    0000026
    111 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4599 Versions of the package jsrsasign from 7.0.0 and before 11.1.1 are vulnerable to Incomplete Comparison with Missing Factors via the getRandomBigIntegerZeroToMax and get… https://www.cve.org/CVERecord?id=CVE-2026-4599

    Post summary

    The statement announces CVE‑2026‑4599, noting that jsrsasign versions 7.0.0 through 11.1.1 are impacted by an incomplete comparison flaw involving the getRandomBigIntegerZeroToMax method.

    0000068
    56.8K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-4599: CRITICAL] Package jsrsasign versions 7.0.0 to 11.1.1 have a vulnerability allowing attackers to recover private keys. The issue lies in incomplete comparison during signature generation.#cve,CVE-2026-4599,#cybersecurity https://cvefind.com/CVE-2026-4599

    Post summary

    The post announces CVE-2026-4599, detailing how jsrsasign packages allow private key recovery via incomplete comparison, but offers no PoC, exploit code, patch, or claim of active exploitation.

    0000043
    605 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-4599 - Critical Versions of the package jsrsasign from 7.0.0 and before 11.1.1 are vulnerable to Incomplete Comparison with Missing Factors via the getRandomBigIntegerZeroToMax and getRandomBigIntegerMinT... https://www.thehackerwire.com/vulnerability/CVE-2026-4599/ https://t.co/CBF6fP5AaW

    Post summary

    A new critical CVE-2026-4599 affecting jsrsasign up to version 11.1.1 has been disclosed, detailing a missing factor in integer comparison operations.

    0000025
    144 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appkjurjsrsasign-node.js-

Explore more