CVE-2026-33895

EUVD-2026-16835
Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, Ed25519 signature verification accepts forged non-canonical signatures where the scalar S is not reduced modulo the group order (`S >= L`). A valid signature and its `S + L` variant both verify in forge, while Node.js `crypto.verify` (OpenSSL-backed) rejects the `S + L` variant, as defined by the specification. This class of signature malleability has been exploited in practice to bypass authentication and authorization logic (see CVE-2026-25793, CVE-2022-35961). Applications relying on signature uniqueness (i.e., dedup by signature bytes, replay tracking, signed-object canonicalization checks) may be bypassed. Version 1.4.0 patches the issue.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 42.64%
Affected Products (NVD)
VendorProductVersion
digitalbazaarforge
𝑥
≤ 1.3.3
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 8
0:2.5.20260422-3.el8ap ≤
𝑥
< *
ADP
Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 9
0:2.5.20260422-3.el9ap ≤
𝑥
< *
ADP
Red HatCluster Observability Operator 1.5.0
1782839279 ≤
𝑥
< *
ADP
Red HatRed Hat Developer Hub 1.8
1776784286 ≤
𝑥
< *
ADP
Red HatRed Hat Developer Hub 1.9
1777903262 ≤
𝑥
< *
ADP
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
node-node-forge
focal
needs-triage
jammy
needs-triage
noble
dne
questing
dne
resolute
dne