CVE-2026-4601 is a critical vulnerability affecting jsrsasign_project jsrsasign versions prior to 11.1.1, stemming from a missing cryptographic step in its DSA signing implementation. This flaw, rated 9.1 Critical (CVSS:3.1/AV:N/AC:L), allows a remote attacker to recover private keys by forcing invalid signatures, leading to high impact on confidentiality and integrity. While no active exploitation or public exploit code is currently available, and community discussion is minimal, immediate patching is recommended due to the severe potential consequences.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 11.1.1CPE matchmatch criteria | cpe:2.3:a:kjur:jsrsasign:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:H/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.