{"id":"GHSA-wvqx-v3f6-w8rh","summary":"jsrsasign: DSA signatures or X.509 certificates can be forged via DSA domain-parameter validation in KJUR.crypto.DSA.setPublic","details":"Versions of the package jsrsasign before 11.1.1 are vulnerable to Improper Verification of Cryptographic Signature via the DSA domain-parameter validation in KJUR.crypto.DSA.setPublic (and the related DSA/X509 verification flow in src/dsa-2.0.js). An attacker can forge DSA signatures or X.509 certificates that X509.verifySignature() accepts by supplying malicious domain parameters such as g=1, y=1, and a fixed r=1, which make the verification equation true for any hash.","aliases":["CVE-2026-4600"],"modified":"2026-07-21T15:15:51.898200332Z","published":"2026-03-23T06:30:29Z","database_specific":{"nvd_published_at":"2026-03-23T06:16:21Z","cwe_ids":["CWE-347"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-03-30T19:29:53Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-4600"},{"type":"WEB","url":"https://github.com/kjur/jsrsasign/pull/646"},{"type":"WEB","url":"https://github.com/kjur/jsrsasign/commit/37b4c06b145c7bfd6bc2a6df5d0a12c56b15ef60"},{"type":"WEB","url":"https://security.snyk.io/vuln/SNYK-JS-JSRSASIGN-15370940"},{"type":"WEB","url":"https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-15812268"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4600.json"},{"type":"PACKAGE","url":"https://github.com/kjur/jsrsasign"},{"type":"WEB","url":"https://gist.github.com/Kr0emer/bf15ddc097176e951659a24a8e9002a7"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2450208"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-4600"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:6926"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:6912"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:6720"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:6568"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:19410"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:19409"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:19375"}],"affected":[{"package":{"name":"jsrsasign","ecosystem":"npm","purl":"pkg:npm/jsrsasign"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"11.1.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-wvqx-v3f6-w8rh/GHSA-wvqx-v3f6-w8rh.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:P"}]}