Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-4601

33
FAUCET Score

CVE-2026-4601 is a critical vulnerability affecting jsrsasign_project jsrsasign versions prior to 11.1.1, stemming from a missing cryptographic step in its DSA signing implementation. This flaw, rated 9.1 Critical (CVSS:3.1/AV:N/AC:L), allows a remote attacker to recover private keys by forcing invalid signatures, leading to high impact on confidentiality and integrity. While no active exploitation or public exploit code is currently available, and community discussion is minimal, immediate patching is recommended due to the severe potential consequences.

Impacted Technologies

VendorProductVersion(s)CPE
< 11.1.1CPE matchmatch criteria
cpe:2.3:a:kjur:jsrsasign:*:*:*:*:*:node.js:*:*

CVSS Data

CVSS version used by this source: 4.0

8.8HIGH

CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:H/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
HIGH
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
NONE
SS Confidentiality
NONE
SS Integrity
HIGH
SS Availability
NONE
Exploit Maturity
PROOF_OF_CONCEPT
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.30%
Probability of exploitation in next 30 days
EPSS Percentile
22.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0030 is in the 3rd percentile among its peer group of 36,835 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (6)

github_advisorypatch availablevia nvd_reference
View patch
npmpatch availablevia ghsa
Product: jsrsasignFixed in: 11.1.1
redhatno patchvia redhat_api
Product: Migration Toolkit for VirtualizationFixed in: migration-toolkit-virtualization/mtv-console-plugin-rhel9
redhatno patchvia redhat_api
Product: Migration Toolkit for VirtualizationFixed in: mtv-candidate/mtv-console-plugin-rhel9
redhatno patchvia redhat_api
Product: Red Hat Quay 3Fixed in: quay/quay-rhel8
redhatno patchvia redhat_api
Product: Red Hat Quay 3Fixed in: quay/quay-rhel9

Vendor Advisories (2)

npmGHSA-w8q8-93cx-6h7rhigh

jsrsasign: Missing cryptographic validation during DSA signing enables private key extraction

Mar 23, 2026
redhatCVE-2026-4601Important

jsrsasign: jsrsasign: Private Key Recovery via Missing Cryptographic Step in DSA Signing

Mar 23, 2026

References

access.redhat.com / errata/RHSA-2026:19375
access.redhat.com / errata/RHSA-2026:19409
access.redhat.com / errata/RHSA-2026:19410
access.redhat.com / errata/RHSA-2026:6568
access.redhat.com / errata/RHSA-2026:6720
access.redhat.com / errata/RHSA-2026:6912
access.redhat.com / errata/RHSA-2026:6926
access.redhat.com / security/cve/CVE-2026-4601
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-4601.json
gist.github.com / Kr0emer/93789fe6efe5519db9692d4ad1dad586
ExploitMitigationThird Party Advisory
github.com / kjur/jsrsasign/commit/0710e392ec35de697ce11e4219c988ba2b5fe0eb
Patch
github.com / kjur/jsrsasign/pull/645
Issue Tracking
security.snyk.io / vuln/SNYK-JAVA-ORGWEBJARSNPM-15812269
security.snyk.io / vuln/SNYK-JS-JSRSASIGN-15370941
Third Party Advisory