Vulnerabilities/

jsrsasign: Incomplete Comparison Allows DSA Private Key Recovery via Biased Nonce Generation

Severity:
High

Description

Versions of the package jsrsasign from 7.0.0 and before 11.1.1 are vulnerable to Incomplete Comparison with Missing Factors via the getRandomBigIntegerZeroToMax and getRandomBigIntegerMinToMax functions in src/crypto-1.1.

Recommendation

Update the jsrsasign package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
jsrsasign
Anything's wrong? Let us know Last updated on March 30, 2026