OsVault/npm/jsrsasign
npm3 critical

jsrsasign

11 known vulnerabilities · 3 critical · 2 high

CVE-2021-30246CRITICAL

RSA signature validation vulnerability on maleable encoded message in jsrsasign

Published Apr 16, 2021
CVE-2026-4598

jsrsasign is vulnerable to DoS through Infinite Loop when processing zero or negative inputs

Published Mar 23, 2026
CVE-2022-25898HIGH

JWS and JWT signature validation vulnerability with special characters

Published Jun 25, 2022
CVE-2026-4602

jsrsasign: Negative Exponent Handling Leads to Signature Verification Bypass

Published Mar 23, 2026
CVE-2026-4603

jsrsasign: Division by Zero Allows Invalid JWK Modulus to Cause Deterministic Zero Output in RSA Operations

Published Mar 23, 2026
CVE-2020-14968CRITICAL

RSA-PSS signature validation vulnerability by prepending zeros in jsrsasign

Published Jun 26, 2020
CVE-2020-14967CRITICAL

RSA PKCS#1 decryption vulnerability with prepending zeros in jsrsasign

Published Jun 26, 2020
CVE-2020-14966HIGH

ECDSA signature validation vulnerability by accepting wrong ASN.1 encoding in jsrsasign

Published Jun 26, 2020
CVE-2026-4601

jsrsasign: Missing cryptographic validation during DSA signing enables private key extraction

Published Mar 23, 2026
CVE-2026-4600

jsrsasign: DSA signatures or X.509 certificates can be forged via DSA domain-parameter validation in KJUR.crypto.DSA.setPublic

Published Mar 23, 2026
CVE-2026-4599

jsrsasign: Incomplete Comparison Allows DSA Private Key Recovery via Biased Nonce Generation

Published Mar 23, 2026
Check your entire dependency tree at onceRun dependency scan →