Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-5m6q-g25r-mvwx | Forge has Denial of Service via Infinite Loop in BigInteger.modInverse() with Zero Input |
Wed, 08 Apr 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:digitalbazaar:forge:*:*:*:*:*:node.js:*:* |
Mon, 30 Mar 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 30 Mar 2026 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Digitalbazaar
Digitalbazaar forge |
|
| Vendors & Products |
Digitalbazaar
Digitalbazaar forge |
Sat, 28 Mar 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-606 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Sat, 28 Mar 2026 03:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, a Denial of Service (DoS) vulnerability exists in the node-forge library due to an infinite loop in the BigInteger.modInverse() function (inherited from the bundled jsbn library). When modInverse() is called with a zero value as input, the internal Extended Euclidean Algorithm enters an unreachable exit condition, causing the process to hang indefinitely and consume 100% CPU. Version 1.4.0 patches the issue. | |
| Title | Forge has Denial of Service via Infinite Loop in BigInteger.modInverse() with Zero Input | |
| Weaknesses | CWE-835 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-30T15:38:12.388Z
Reserved: 2026-03-24T15:10:05.682Z
Link: CVE-2026-33891
Updated: 2026-03-30T15:38:08.073Z
Status : Analyzed
Published: 2026-03-27T21:17:25.817
Modified: 2026-04-08T13:50:28.880
Link: CVE-2026-33891
OpenCVE Enrichment
Updated: 2026-04-08T20:00:53Z
Github GHSA