CVE-2026-33895 describes a high-severity vulnerability in Forge (node-forge) prior to version 1.4.0, where its Ed25519 signature verification accepts forged non-canonical signatures. Rated 7.5 CVSS (High), this flaw allows remote attackers to bypass authentication and authorization logic or other signature uniqueness checks due to signature malleability. The attack requires no privileges or user interaction and has a high impact on integrity. While there is no evidence of active exploitation for this specific CVE, this class of signature malleability has been exploited in other contexts, and the vulnerability has seen some community discussion. Organizations are advised to upgrade to Forge version 1.4.0 to remediate this issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.3.3CPE matchmatch criteria | cpe:2.3:a:digitalbazaar:forge:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.