Vulnerabilities/

Forge has signature forgery in RSA-PKCS due to ASN.1 extra field

Severity:
High

Description

RSASSA PKCS#1 v1.5 signature verification accepts forged signatures for low public exponent keys (e=3). Attackers can forge signatures by stuffing “garbage” bytes within the ASN structure in order to construct a signature that passes verification, enabling Bleichenbacher style forgery.

Recommendation

Update the node-forge package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
node-forge
Anything's wrong? Let us know Last updated on March 27, 2026