Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-33894

31
FAUCET Score

CVE-2026-33894 is a high-severity vulnerability (CVSS 7.5) affecting Forge (node-forge) versions prior to 1.4.0, allowing attackers to forge RSASSA PKCS#1 v1.5 signatures. This flaw, exploitable over the network with low complexity, enables Bleichenbacher style forgery by manipulating ASN.1 structures or insufficient padding, resulting in a high integrity impact. While the vulnerability has a very low EPSS score and some community mentions, there is currently no evidence of active exploitation, nor are public exploit modules available.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.4.0CPE matchmatch criteria
cpe:2.3:a:digitalbazaar:forge:*:*:*:*:*:node.js:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.47%
Probability of exploitation in next 30 days
EPSS Percentile
38.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0047 is in the 17th percentile among its peer group of 51,506 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

npmpatch availablevia ghsa
Product: node-forgeFixed in: 1.4.0
github_advisoryvendor investigatingvia nvd_reference
View patch

Vendor Advisories (1)

npmGHSA-ppp5-5v6c-4jwphigh

Forge has signature forgery in RSA-PKCS due to ASN.1 extra field

Mar 26, 2026

References

access.redhat.com / errata/RHSA-2026:13826
access.redhat.com / errata/RHSA-2026:19375
access.redhat.com / errata/RHSA-2026:21017
access.redhat.com / errata/RHSA-2026:22465
access.redhat.com / errata/RHSA-2026:22629
access.redhat.com / errata/RHSA-2026:22840
access.redhat.com / errata/RHSA-2026:23361
access.redhat.com / errata/RHSA-2026:24761
access.redhat.com / errata/RHSA-2026:24853
access.redhat.com / errata/RHSA-2026:34342
access.redhat.com / errata/RHSA-2026:9742
access.redhat.com / security/cve/CVE-2026-33894
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-33894.json
datatracker.ietf.org / doc/html/rfc2313
Third Party Advisory
github.com / digitalbazaar/forge/security/advisories/GHSA-ppp5-5v6c-4jwp
Vendor Advisory
mailarchive.ietf.org / arch/msg/openpgp/5rnE9ZRN1AokBVj3VqblGlP63QE
Third Party Advisory
rfc-editor.org / rfc/rfc8017.html
Third Party Advisory