CVE-2026-33896 identifies a high-severity vulnerability in the Forge (node-forge) JavaScript library, affecting versions prior to 1.4.0. This flaw allows an attacker to craft a leaf certificate that can impersonate a Certificate Authority (CA) due to the library's failure to properly enforce RFC 5280 basicConstraints during certificate chain validation. Rated 7.4 (High) on the CVSS scale, it presents a network attack vector with high complexity, potentially leading to high impact on confidentiality and integrity through spoofing or man-in-the-middle attacks. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion regarding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.3.3CPE matchmatch criteria | cpe:2.3:a:digitalbazaar:forge:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.