Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-5jx8-q4cp-rhh6 | jsrsasign: Incomplete Comparison Allows DSA Private Key Recovery via Biased Nonce Generation |
Mon, 23 Mar 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jsrsasign Project
Jsrsasign Project jsrsasign |
|
| CPEs | cpe:2.3:a:jsrsasign_project:jsrsasign:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Jsrsasign Project
Jsrsasign Project jsrsasign |
Mon, 23 Mar 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 23 Mar 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | jsrsasign: jsrsasign: Private key recovery via incomplete comparison checks biasing DSA nonces | |
| Weaknesses | CWE-338 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Mon, 23 Mar 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Kjur
Kjur jsrsasign |
|
| Vendors & Products |
Kjur
Kjur jsrsasign |
Mon, 23 Mar 2026 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Versions of the package jsrsasign from 7.0.0 and before 11.1.1 are vulnerable to Incomplete Comparison with Missing Factors via the getRandomBigIntegerZeroToMax and getRandomBigIntegerMinToMax functions in src/crypto-1.1.js; an attacker can recover the private key by exploiting the incorrect compareTo checks that accept out-of-range candidates and thus bias DSA nonces during signature generation. | |
| Weaknesses | CWE-1023 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: snyk
Published:
Updated: 2026-03-23T14:39:45.496Z
Reserved: 2026-03-22T16:25:57.565Z
Link: CVE-2026-4599
Updated: 2026-03-23T14:39:42.517Z
Status : Analyzed
Published: 2026-03-23T06:16:21.513
Modified: 2026-03-23T16:17:45.400
Link: CVE-2026-4599
OpenCVE Enrichment
Updated: 2026-03-25T14:49:49Z
Github GHSA