Tag
high
advisory
Forge Ed25519 Signature Forgery Vulnerability
2 rules 1 TTPForge is vulnerable to signature forgery in Ed25519 due to a missing check that S < L, allowing non-canonical signatures and potentially bypassing authentication/authorization logic, affecting versions before 1.4.0.
ed25519
signature-forgery
forge
javascript
2r
1t
high
advisory
Forge RSA Signature Forgery Vulnerability
2 rules 1 TTP 2 CVEsForge is vulnerable to signature forgery in RSA-PKCS due to ASN.1 extra field, allowing attackers to forge signatures by stuffing garbage bytes within the ASN structure for low public exponent keys (e=3), enabling Bleichenbacher style forgery and affecting npm/node-forge versions less than 1.4.0.
node-forge
forge
rsa
signature-forgery
bleichenbacher
2r
1t
2c
updated