Digital Bazaar maintains a narrowly scoped cryptographic toolkit, principally its Forge library, that serves as an underlying component in JavaScript-based security applications and web services. The vendor's vulnerability profile centers on signature-verification and certificate-validation weaknesses alongside prototype-pollution and integer-overflow conditions that recur in the library, reflecting the complexity of implementing cryptographic standards and secure object handling in JavaScript. Defenders integrating Forge should prioritize updates addressing certificate and signature validation; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Digitalbazaar over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-33896CRITICAL Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, `pki.verifyCertificateChain()` does not enforce RFC 5 | Mar 27, 2026 | 9.1 | 37 | NO | NO |
CVE-2025-12816HIGH An interpretation-conflict (CWE-436) vulnerability in node-forge versions 1.3.1 and earlier enables unauthenticated attackers to craft ASN.1 structures to desynchronize schema vali | Nov 25, 2025 | 8.6 | 32 | NO | NO |
CVE-2026-33894HIGH Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, RSASSA PKCS#1 v1.5 signature verification accepts for | Mar 27, 2026 | 7.5 | 31 | NO | NO |
CVE-2026-33895HIGH Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, Ed25519 signature verification accepts forged non-can | Mar 27, 2026 | 7.5 | 30 | NO | NO |
CVE-2026-33891HIGH Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, a Denial of Service (DoS) vulnerability exists in the | Mar 27, 2026 | 7.5 | 30 | NO | NO |
CVE-2025-66031HIGH Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Uncontrolled Recursion vulnerability in node-forge versions 1.3.1 and belo | Nov 26, 2025 | 7.5 | 27 | NO | NO |
CVE-2022-24772HIGH Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.3.0, RSA PKCS#1 v1.5 signature verification code does not | Mar 18, 2022 | 7.5 | 26 | NO | NO |
CVE-2022-24771HIGH Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.3.0, RSA PKCS#1 v1.5 signature verification code is lenien | Mar 18, 2022 | 7.5 | 25 | NO | NO |
CVE-2025-66030MEDIUM Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Integer Overflow vulnerability in node-forge versions 1.3.1 and below enab | Nov 26, 2025 | 5.3 | 20 | NO | NO |
CVE-2022-24773MEDIUM Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.3.0, RSA PKCS#1 v1.5 signature verification code does not | Mar 18, 2022 | 5.3 | 20 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Digitalbazaar.
Media articles that mention a CVE ID that affects a product developed by Digitalbazaar — matched by CVE ID, not by vendor name.