digitalbazaar records
12 published records for vendor digitalbazaar.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-347 Improper Verification of Cryptographic Signature4
- CWE-190 Integer Overflow or Wraparound1
- CWE-20 Improper Input Validation1
- CWE-295 Improper Certificate Validation1
- CWE-436 Interpretation Conflict1
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
12 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
36Monitor | CVE-2026-33896No exploit | Forge has a basicConstraints bypass in its certificate chain verification (RFC 5280 violation)digitalbazaar · forge · CWE-295 | Critical9.1 | — | 0.5% | Mar 27, 2026 |
34Monitor | CVE-2025-12816No exploit | An interpretation-conflict (CWE-436) vulnerability in node-forge versions 1.3.1 and earlier enables unauthenticated attackers to craft ASN.1digitalbazaar · forge · CWE-436 | High8.6 | — | 0.7% | Nov 25, 2025 |
34Monitor | CVE-2025-66031No exploit | node-forge ASN.1 Unbounded Recursiondigitalbazaar · forge · CWE-674 | High8.7 | — | 0.4% | Nov 26, 2025 |
30Monitor | CVE-2020-7720No exploit | The package node-forge before 0.10.0 is vulnerable to Prototype Pollution via the util.setPath function.digitalbazaar · forge · CWE-1321 | High7.3 | — | 3.2% | Sep 1, 2020 |
30Monitor | CVE-2022-24772No exploit | Improper Verification of Cryptographic Signature in `node-forge`digitalbazaar · forge · CWE-347 | High7.5 | — | 1.1% | Mar 18, 2022 |
30Monitor | CVE-2026-33891No exploit | Forge has Denial of Service via Infinite Loop in BigInteger.modInverse() with Zero Inputdigitalbazaar · forge · CWE-835 | High7.5 | — | 0.9% | Mar 27, 2026 |
30Monitor | CVE-2022-24771No exploit | Improper Verification of Cryptographic Signature in node-forgedigitalbazaar · forge · CWE-347 | High7.5 | — | 0.8% | Mar 18, 2022 |
30Monitor | CVE-2026-33895No exploit | Forge has signature forgery in Ed25519 due to missing S > L checkdigitalbazaar · forge · CWE-347 | High7.5 | — | 0.5% | Mar 27, 2026 |
30Monitor | CVE-2026-33894No exploit | Forge has signature forgery in RSA-PKCS due to ASN.1 extra fielddigitalbazaar · forge · CWE-20 | High7.5 | — | 0.4% | Mar 27, 2026 |
25Monitor | CVE-2025-66030No exploit | node-forge ASN.1 OID Integer Truncationdigitalbazaar · forge · CWE-190 | Medium6.3 | — | 0.3% | Nov 26, 2025 |
24Monitor | CVE-2022-0122No exploit | Open Redirect in digitalbazaar/forgedigitalbazaar · forge · CWE-601 | Medium6.1 | — | 0.8% | Jan 6, 2022 |
21Monitor | CVE-2022-24773No exploit | Improper Verification of Cryptographic Signature in `node-forge`digitalbazaar · forge · CWE-347 | Medium5.3 | — | 1.0% | Mar 18, 2022 |
- CVE-2026-3389636Monitor
Forge has a basicConstraints bypass in its certificate chain verification (RFC 5280 violation)
CriticalCVSS 9.1No exploitEPSS 1%digitalbazaar · forgeMar 27, 2026
- CVE-2025-1281634Monitor
An interpretation-conflict (CWE-436) vulnerability in node-forge versions 1.3.1 and earlier enables unauthenticated attackers to craft ASN.1
HighCVSS 8.6No exploitEPSS 1%digitalbazaar · forgeNov 25, 2025
- CVE-2025-6603134Monitor
node-forge ASN.1 Unbounded Recursion
HighCVSS 8.7No exploitEPSS 0%digitalbazaar · forgeNov 26, 2025
- CVE-2020-772030Monitor
The package node-forge before 0.10.0 is vulnerable to Prototype Pollution via the util.setPath function.
HighCVSS 7.3No exploitEPSS 3%digitalbazaar · forgeSep 1, 2020
- CVE-2022-2477230Monitor
Improper Verification of Cryptographic Signature in `node-forge`
HighCVSS 7.5No exploitEPSS 1%digitalbazaar · forgeMar 18, 2022
- CVE-2026-3389130Monitor
Forge has Denial of Service via Infinite Loop in BigInteger.modInverse() with Zero Input
HighCVSS 7.5No exploitEPSS 1%digitalbazaar · forgeMar 27, 2026
- CVE-2022-2477130Monitor
Improper Verification of Cryptographic Signature in node-forge
HighCVSS 7.5No exploitEPSS 1%digitalbazaar · forgeMar 18, 2022
- CVE-2026-3389530Monitor
Forge has signature forgery in Ed25519 due to missing S > L check
HighCVSS 7.5No exploitEPSS 0%digitalbazaar · forgeMar 27, 2026
- CVE-2026-3389430Monitor
Forge has signature forgery in RSA-PKCS due to ASN.1 extra field
HighCVSS 7.5No exploitEPSS 0%digitalbazaar · forgeMar 27, 2026
- CVE-2025-6603025Monitor
node-forge ASN.1 OID Integer Truncation
MediumCVSS 6.3No exploitEPSS 0%digitalbazaar · forgeNov 26, 2025
- CVE-2022-012224Monitor
Open Redirect in digitalbazaar/forge
MediumCVSS 6.1No exploitEPSS 1%digitalbazaar · forgeJan 6, 2022
- CVE-2022-2477321Monitor
Improper Verification of Cryptographic Signature in `node-forge`
MediumCVSS 5.3No exploitEPSS 1%digitalbazaar · forgeMar 18, 2022