Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-33896

37
FAUCET Score

CVE-2026-33896 identifies a high-severity vulnerability in the Forge (node-forge) JavaScript library, affecting versions prior to 1.4.0. This flaw allows an attacker to craft a leaf certificate that can impersonate a Certificate Authority (CA) due to the library's failure to properly enforce RFC 5280 basicConstraints during certificate chain validation. Rated 7.4 (High) on the CVSS scale, it presents a network attack vector with high complexity, potentially leading to high impact on confidentiality and integrity through spoofing or man-in-the-middle attacks. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion regarding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
<= 1.3.3CPE matchmatch criteria
cpe:2.3:a:digitalbazaar:forge:*:*:*:*:*:node.js:*:*

CVSS Data

CVSS version used by this source: 3.1

7.4HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
2.2
Impact Score
5.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.35%
Probability of exploitation in next 30 days
EPSS Percentile
27.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0035 is in the 5th percentile among its peer group of 36,862 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

github_advisorypatch availablevia nvd_reference
View patch
npmpatch availablevia ghsa
Product: node-forgeFixed in: 1.4.0

Vendor Advisories (2)

npmGHSA-2328-f5f3-gj25high

Forge has a basicConstraints bypass in its certificate chain verification (RFC 5280 violation)

Mar 26, 2026
microsoft2026-Mar/CVE-2026-33896Important

Forge has a basicConstraints bypass in its certificate chain verification (RFC 5280 violation)

Mar 10, 2026

References

access.redhat.com / errata/RHSA-2026:13826
access.redhat.com / errata/RHSA-2026:24761
access.redhat.com / errata/RHSA-2026:34342
access.redhat.com / errata/RHSA-2026:9742
access.redhat.com / security/cve/CVE-2026-33896
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-33896.json
github.com / digitalbazaar/forge/commit/2e492832fb25227e6b647cbe1ac981c123171e90
Patch
github.com / digitalbazaar/forge/security/advisories/GHSA-2328-f5f3-gj25
ExploitVendor Advisory