CVE-2026-4601
Versions of the package jsrsasign before 11.1.1 are vulnerable to Missing Cryptographic Step via the KJUR.crypto.DSA.signWithMessageHash process in the DSA signing implementation. An attacker can recover the private key by forcing r or s to be zero, so the library emits an invalid signature without retrying, and then solves for x from the resulting signature.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.4
- CVSS vector
- CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:H/SA:N/E:P
- EPSS probability
- 0.30%
- CWE
- CWE-325
- Published
- 2026-03-23
- Last modified
- 2026-09-07
Affected products
- n/a jsrsasign
- n/a org.webjars.npm:jsrsasign
Weakness type
Related vulnerabilities
- CVE-2026-25250 — EAZ EazyFix 12.9 allows a Security Feature Bypass related to a "Missing Cryptographic Step"...
- CVE-2026-76784 — Insufficient Cryptographic Protections in Local Device Communication Protocol on Multiple TP-Link Kasa Smart Home Devices
- CVE-2026-59776 — Missing Cryptographic Step (CWE-325) vulnerability exists in certain FeliCa IC chips shipped in or...
- CVE-2026-58638 — Windows Boot Loader Security Feature Bypass Vulnerability
- CVE-2026-55144 — Windows Cryptography API: Next Generation (CNG) Tampering Vulnerability
- CVE-2026-6458 — AES-256-GCM Authentication Tag Does Not Cover First Ciphertext Blocks When AAD Is Empty
- CVE-2026-49440 — Deno: Miller-Rabin Primality Test Allows Zero Rounds
- CVE-2026-9266 — A Missing Required Cryptographic Step vulnerability has been identified in Moxa's embedded Linux...