CVE-2026-4601General(kjur / jsrsasign)

LOWCVSS 9.1 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch kjur jsrsasign systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Versions of the package jsrsasign before 11.1.1 are vulnerable to Missing Cryptographic Step via the KJUR.crypto.DSA.signWithMessageHash process in the DSA signing implementation. An attacker can recover the private key by forcing r or s to be zero, so the library emits an invalid signature without retrying, and then solves for x from the resulting signature.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-325

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • jsrsasign

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 7 signals
  • General: 4 classified signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 5 mentions (2026-03-23); latest day: 2
  • 8 total mentions across 3 days

Affected systems

Vendors
Products
jsrsasign

Deep dive

Activity timeline8 mentions / 3d
01345Mentions · 2026-03-23: 5Mentions · 2026-03-27: 1Mentions · 2026-03-28: 2Patch / Workaround · 2026-03-23: 1Technical Details · 2026-03-23: 4Technical Details · 2026-03-27: 1Technical Details · 2026-03-28: 203-2303-2703-28
Signal classification3 categories
General
450.0%
Disclosure
337.5%
Patch
112.5%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-235
Disclosure3General1Patch1
2026-03-271
General1
2026-03-282
General2
Full discourse8 posts
  • z3n@zench4n
    General

    Cryptographic vulnerabilities like CVE-2026-4600 and CVE-2026-4601 (jsrsasign) are critical. AI agents relying on compromised crypto for data integrity or authentication face severe trust issues.

    Post summary

    The post notes that CVE-2026-4600 and CVE-2026-4601 are critical cryptographic flaws in jsrsasign, stressing the impact on AI agents that rely on cryptography for trust.

    100107
    1.4K followersView on X
  • z3n@zench4n
    General

    Consider `RTOSploit` for embedded AI. A deep dive examines how cryptographic failures (`CVE-2026-4600`, `CVE-2026-4601`) impact agent integrity and trust, not just component security.

    Post summary

    The passage references cryptographic failures in CVE-2026-4600 and CVE-2026-4601, impacting agent integrity and trust, but offers no PoC, exploit details, or remediation information.

    1000032
    1.4K followersView on X
  • z3n@zench4n
    General

    Cryptographic vulnerabilities like CVE-2026-4600 and CVE-2026-4601 (jsrsasign) are critical. AI agents relying on compromised crypto for data integrity or authentication face severe trust issues.

    Post summary

    The statement highlights that CVE-2026-4600 and CVE-2026-4601 are critical cryptographic flaws in jsrsasign, potentially jeopardizing AI agents that rely on them, but provides no further technical or operational details.

    1000020
    1.4K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-4601 📊 Severity: 8.7 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-4601 #CVE-2026-4601 #CVE #High  #CyberSecurity #InfoSec https://t.co/IBP5vMNATZ

    Post summary

    The tweet announces a new high‑severity CVE (CVE‑2026‑4601) with reference to the NVD, but it does not provide details on exploitation, patches, or technical aspects.

    0000032
    111 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4601 Versions of the package jsrsasign before 11.1.1 are vulnerable to Missing Cryptographic Step via the KJUR.crypto.DSA.signWithMessageHash process in the DSA signing impl… https://www.cve.org/CVERecord?id=CVE-2026-4601

    Post summary

    The text announces CVE‑2026‑4601, noting a missing cryptographic step in jsrsasign versions prior to 11.1.1, but provides no PoC, exploit code, active exploitation evidence, or patch information.

    0000070
    56.8K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-4601 Cryptographic Vulnerability in jsrsasign Before 11.1.1 Enabling Private Key Recovery https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4601

    Post summary

    CVE-2026-4601 reveals a cryptographic flaw in jsrsasign before version 11.1.1 that could allow private key recovery; the brief provides technical detail but no PoC, exploitation evidence, or patch information.

    0000053
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-4601: HIGH] jsrsasign package <11.1.1 is at risk due to a Missing Cryptographic Step in DSA signing process. Attackers could exploit this to recover private keys. Update now to secure your system.#cve,CVE-2026-4601,#cybersecurity https://cvefind.com/CVE-2026-4601

    Post summary

    The post highlights a high‑severity vulnerability, CVE-2026-4601, in jsrsasign <11.1.1 that could allow attackers to recover private keys; it urges users to update their software.

    0000053
    605 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-4601 - High Versions of the package jsrsasign before 11.1.1 are vulnerable to Missing Cryptographic Step via the KJUR.crypto.DSA.signWithMessageHash process in the DSA signing implementation. An attacker ... https://www.thehackerwire.com/vulnerability/CVE-2026-4601/ https://t.co/LXQBL5dxBk

    Post summary

    The text announces CVE‑2026‑4601 as a high‑severity vulnerability in jsrsasign (v<11.1.1) due to a missing cryptographic step, providing technical details but no exploit, patch, or PoC information.

    0000028
    144 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appkjurjsrsasign-node.js-

Explore more