CVE-2026-4600General(kjur / jsrsasign)

LOWCVSS 9.1 · CRITICAL

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Versions of the package jsrsasign before 11.1.1 are vulnerable to Improper Verification of Cryptographic Signature via the DSA domain-parameter validation in KJUR.crypto.DSA.setPublic (and the related DSA/X509 verification flow in src/dsa-2.0.js). An attacker can forge DSA signatures or X.509 certificates that X509.verifySignature() accepts by supplying malicious domain parameters such as g=1, y=1, and a fixed r=1, which make the verification equation true for any hash.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-347

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • jsrsasign

Threat summary

  • Public PoC is present in monitored signal
  • 7 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 3 signals
  • General: 4 classified signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 4 mentions (2026-03-23); latest day: 2
  • 7 total mentions across 3 days

Affected systems

Vendors
Products
jsrsasign

Deep dive

Activity timeline7 mentions / 3d
01234Mentions · 2026-03-23: 4Mentions · 2026-03-27: 1Mentions · 2026-03-28: 2PoC Mentioned / Linked · 2026-03-23: 1Technical Details · 2026-03-23: 303-2303-2703-28
Signal classification3 categories
General
457.1%
Disclosure
228.6%
PoC
114.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-234
Disclosure2General1PoC1
2026-03-271
General1
2026-03-282
General2
Full discourse7 posts
  • z3n@zench4n
    General

    Cryptographic vulnerabilities like CVE-2026-4600 and CVE-2026-4601 (jsrsasign) are critical. AI agents relying on compromised crypto for data integrity or authentication face severe trust issues.

    Post summary

    The post notes that CVE-2026-4600 and CVE-2026-4601 in jsrsasign are critical but offers no further technical or operational details.

    100107
    1.4K followersView on X
  • z3n@zench4n
    General

    Consider `RTOSploit` for embedded AI. A deep dive examines how cryptographic failures (`CVE-2026-4600`, `CVE-2026-4601`) impact agent integrity and trust, not just component security.

    Post summary

    The text briefly notes cryptographic failures in CVE-2026‑4600 and CVE-2026‑4601 affecting agent integrity in embedded AI, but provides no further detail or actionable information.

    1000032
    1.4K followersView on X
  • z3n@zench4n
    General

    Cryptographic vulnerabilities like CVE-2026-4600 and CVE-2026-4601 (jsrsasign) are critical. AI agents relying on compromised crypto for data integrity or authentication face severe trust issues.

    Post summary

    The passage merely notes that CVE-2026-4600 and CVE-2026-4601 in jsrsasign are critical and may affect AI agents’ trust, without providing technical specifics, exploit details, or mitigation information.

    1000020
    1.4K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-4600 DSA Signature Verification Bypass in Jsrsasign Before 11.1.1 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4600

    Post summary

    The text announces CVE‑2026‑4600, a DSA signature verification bypass affecting Jsrsasign versions prior to 11.1.1, without mentioning PoC, exploit code, or patches.

    0001059
    4.0K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-4600 📊 Severity: 7.4 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-4600 #CVE-2026-4600 #CVE #High  #CyberSecurity #InfoSec https://t.co/WetmA6Pfbd

    Post summary

    The tweet announces a new CVE with a severity rating but lacks technical details, PoC, exploit code, patch info, or active exploitation evidence.

    0000031
    111 followersView on X
  • 0day Signal@0dayPublishing
    PoC

    🚨 CVE-2026-4600: n/a (CVSS: 9.1)... DSA domain parameter bypass (g=1, y=1, r=1) lets attackers forge any X.509 cert or signature that jsrsasign will accept—... https://zerodaysignal.com/vulnerability/CVE-2026-4600 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces CVE‑2026‑4600, provides a link to a ZeroDaySignal analysis, and describes a DSA parameter bypass that can forge certificates, but does not supply exploit code or mention active exploitation.

    0000057
    162 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4600 Versions of the package jsrsasign before 11.1.1 are vulnerable to Improper Verification of Cryptographic Signature via the DSA domain-parameter validation in KJUR.crypt… https://www.cve.org/CVERecord?id=CVE-2026-4600

    Post summary

    The post announces CVE-2026-4600 affecting jsrsasign versions older than 11.1.1 due to improper DSA domain‑parameter validation, providing vulnerability details but no PoC, exploit, or patch information.

    0000084
    56.8K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appkjurjsrsasign-node.js-

Explore more