The number and severity of CVEs published that impact products developed by Kjur over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-4599CRITICAL Versions of the package jsrsasign from 7.0.0 and before 11.1.1 are vulnerable to Incomplete Comparison with Missing Factors via the getRandomBigIntegerZeroToMax and getRandomBigInt | Mar 23, 2026 | 9.1 | 34 | NO | NO |
CVE-2026-4601CRITICAL Versions of the package jsrsasign before 11.1.1 are vulnerable to Missing Cryptographic Step via the KJUR.crypto.DSA.signWithMessageHash process in the DSA signing implementation. | Mar 23, 2026 | 9.1 | 33 | NO | NO |
CVE-2026-4600CRITICAL Versions of the package jsrsasign before 11.1.1 are vulnerable to Improper Verification of Cryptographic Signature via the DSA domain-parameter validation in KJUR.crypto.DSA.setPub | Mar 23, 2026 | 9.1 | 32 | NO | NO |
CVE-2022-25898CRITICAL The package jsrsasign before 10.5.25 are vulnerable to Improper Verification of Cryptographic Signature when JWS or JWT signature with non Base64URL encoding special characters or | Jul 1, 2022 | 9.8 | 32 | NO | NO |
CVE-2020-14967CRITICAL An issue was discovered in the jsrsasign package before 8.0.18 for Node.js. Its RSA PKCS1 v1.5 decryption implementation does not detect ciphertext modification by prepending '\0' | Jun 22, 2020 | 9.8 | 32 | NO | NO |
CVE-2026-4602HIGH Versions of the package jsrsasign before 11.1.1 are vulnerable to Incorrect Conversion between Numeric Types due to handling negative exponents in ext/jsbn2.js. An attacker can for | Mar 23, 2026 | 7.5 | 29 | NO | NO |
CVE-2026-4598HIGH Versions of the package jsrsasign before 11.1.1 are vulnerable to Infinite loop via the bnModInverse function in ext/jsbn2.js when the BigInteger.modInverse implementation receives | Mar 23, 2026 | 7.5 | 29 | NO | NO |
CVE-2020-14968CRITICAL An issue was discovered in the jsrsasign package before 8.0.17 for Node.js. Its RSASSA-PSS (RSA-PSS) implementation does not detect signature manipulation/modification by prependin | Jun 22, 2020 | 9.8 | 28 | NO | NO |
CVE-2021-30246CRITICAL In the jsrsasign package through 10.1.13 for Node.js, some invalid RSA PKCS#1 v1.5 signatures are mistakenly recognized to be valid. NOTE: there is no known practical attack. | Apr 7, 2021 | 9.1 | 27 | NO | NO |
CVE-2020-14966HIGH An issue was discovered in the jsrsasign package through 8.0.18 for Node.js. It allows a malleability in ECDSA signatures by not checking overflows in the length of a sequence and | Jun 22, 2020 | 7.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Kjur.
Media articles that mention a CVE ID that affects a product developed by Kjur — matched by CVE ID, not by vendor name.