CVE-2026-4599

Versions of the package jsrsasign from 7.0.0 and before 11.1.1 are vulnerable to Incomplete Comparison with Missing Factors via the getRandomBigIntegerZeroToMax and getRandomBigIntegerMinToMax functions in src/crypto-1.1.js; an attacker can recover the private key by exploiting the incorrect compareTo checks that accept out-of-range candidates and thus bias DSA nonces during signature generation.
Configurations

Configuration 1 (hide)

cpe:2.3:a:kjur:jsrsasign:*:*:*:*:*:node.js:*:*

History

30 Jun 2026, 03:20

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:19375 -
  • () https://access.redhat.com/errata/RHSA-2026:19409 -
  • () https://access.redhat.com/errata/RHSA-2026:19410 -
  • () https://access.redhat.com/errata/RHSA-2026:6568 -
  • () https://access.redhat.com/errata/RHSA-2026:6720 -
  • () https://access.redhat.com/errata/RHSA-2026:6912 -
  • () https://access.redhat.com/errata/RHSA-2026:6926 -
  • () https://access.redhat.com/security/cve/CVE-2026-4599 -
  • () https://bugzilla.redhat.com/show_bug.cgi?id=2450207 -
  • () https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4599.json -
CWE CWE-338

25 Jun 2026, 16:16

Type Values Removed Values Added
References
  • () https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-15812264 -

22 Jun 2026, 03:18

Type Values Removed Values Added
CPE cpe:2.3:a:jsrsasign_project:jsrsasign:*:*:*:*:*:node.js:*:* cpe:2.3:a:kjur:jsrsasign:*:*:*:*:*:node.js:*:*
First Time Kjur
Kjur jsrsasign

17 Jun 2026, 10:56

Type Values Removed Values Added
Summary
  • (es) Versiones del paquete jsrsasign desde la 7.0.0 y hasta la 11.1.1 son vulnerables a Comparación Incompleta con Factores Faltantes a través de las funciones getRandomBigIntegerZeroToMax y getRandomBigIntegerMinToMax en src/crypto-1.1.js; un atacante puede recuperar la clave privada explotando las comprobaciones compareTo incorrectas que aceptan candidatos fuera de rango y, por lo tanto, sesgan los nonces DSA durante la generación de firmas.

23 Mar 2026, 16:17

Type Values Removed Values Added
References () https://gist.github.com/Kr0emer/081681818b51605c91945126d74b4f20 - () https://gist.github.com/Kr0emer/081681818b51605c91945126d74b4f20 - Exploit, Mitigation, Third Party Advisory
References () https://github.com/kjur/jsrsasign/commit/ee4b013478366cb16cea9a4bdfb218b6077f83b1 - () https://github.com/kjur/jsrsasign/commit/ee4b013478366cb16cea9a4bdfb218b6077f83b1 - Patch
References () https://github.com/kjur/jsrsasign/pull/647 - () https://github.com/kjur/jsrsasign/pull/647 - Issue Tracking
References () https://security.snyk.io/vuln/SNYK-JS-JSRSASIGN-15370939 - () https://security.snyk.io/vuln/SNYK-JS-JSRSASIGN-15370939 - Third Party Advisory
First Time Jsrsasign Project
Jsrsasign Project jsrsasign
CPE cpe:2.3:a:jsrsasign_project:jsrsasign:*:*:*:*:*:node.js:*:*

23 Mar 2026, 06:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-23 06:16

Updated : 2026-07-20 12:19


NVD link : CVE-2026-4599

Mitre link : CVE-2026-4599

CVE.ORG link : CVE-2026-4599


JSON object : View

Products Affected

kjur

  • jsrsasign
CWE
CWE-1023

Incomplete Comparison with Missing Factors

CWE-338

Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)