Forge
Vendor:
First CVE: Sep 1, 2020 · Active for 5 years
12
Total CVEs
More Total CVEs than 90% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
7.2
Avg CVSS
Higher Avg CVSS than 45% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Forge over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 1, 2020
5 years ago
Most Recent CVE
Mar 27, 2026
119 days ago
CVE Severity & Scoring
Forge12 CVEs
25%
67%
8%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network12 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None11 (91.7%)
Unknown0 (0.0%)
Required1 (8.3%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None12 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-33896CRITICAL Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, `pki.verifyCertificateChain()` does not enforce RFC 5 | Mar 27, 2026 | 9.1 | 37 | NO | NO |
CVE-2025-12816HIGH An interpretation-conflict (CWE-436) vulnerability in node-forge versions 1.3.1 and earlier enables unauthenticated attackers to craft ASN.1 structures to desynchronize schema vali | Nov 25, 2025 | 8.6 | 32 | NO | NO |
CVE-2026-33894HIGH Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, RSASSA PKCS#1 v1.5 signature verification accepts for | Mar 27, 2026 | 7.5 | 31 | NO | NO |
CVE-2026-33895HIGH Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, Ed25519 signature verification accepts forged non-can | Mar 27, 2026 | 7.5 | 30 | NO | NO |
CVE-2026-33891HIGH Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, a Denial of Service (DoS) vulnerability exists in the | Mar 27, 2026 | 7.5 | 30 | NO | NO |
CVE-2025-66031HIGH Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Uncontrolled Recursion vulnerability in node-forge versions 1.3.1 and belo | Nov 26, 2025 | 7.5 | 27 | NO | NO |
CVE-2022-24772HIGH Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.3.0, RSA PKCS#1 v1.5 signature verification code does not | Mar 18, 2022 | 7.5 | 26 | NO | NO |
CVE-2022-24771HIGH Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.3.0, RSA PKCS#1 v1.5 signature verification code is lenien | Mar 18, 2022 | 7.5 | 25 | NO | NO |
CVE-2025-66030MEDIUM Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Integer Overflow vulnerability in node-forge versions 1.3.1 and below enab | Nov 26, 2025 | 5.3 | 20 | NO | NO |
CVE-2022-24773MEDIUM Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.3.0, RSA PKCS#1 v1.5 signature verification code does not | Mar 18, 2022 | 5.3 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (12 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (12 CVEs).
Media Mentions
Signals from CVEs in this product scope (12 CVEs).
Top CNAs Publishing CVEs For Forge
Top CWEs
Versions
No cataloged versions.