VendorsDigital Bazaarforgeall versions
Vulnerabilities

Digital Bazaar Forge

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

12CVEs
CVE-2020-7720
Prototype Pollution
Published 2020-09-01 · Modified
9.8EPSS 0.032
CVE-2026-33896
Forge has a basicConstraints bypass in its certificate chain verification (RFC 5280 violation)
Published 2026-03-27 · Modified
9.1EPSS 0.003
CVE-2025-66031
node-forge ASN.1 Unbounded Recursion
Published 2025-11-26 · Analyzed
8.7EPSS 0.004
CVE-2025-12816
CVE-2025-12816
Published 2025-11-25 · Analyzed
8.6EPSS 0.007
CVE-2022-24772
Improper Verification of Cryptographic Signature in `node-forge`
Published 2022-03-18 · Modified
7.5EPSS 0.011
CVE-2022-24771
Improper Verification of Cryptographic Signature in node-forge
Published 2022-03-18 · Modified
7.5EPSS 0.008
CVE-2026-33891
Forge has Denial of Service via Infinite Loop in BigInteger.modInverse() with Zero Input
Published 2026-03-27 · Modified
7.5EPSS 0.006
CVE-2026-33895
Forge has signature forgery in Ed25519 due to missing S > L check
Published 2026-03-27 · Modified
7.5EPSS 0.005
CVE-2026-33894
Forge has signature forgery in RSA-PKCS due to ASN.1 extra field
Published 2026-03-27 · Modified
7.5EPSS 0.005
CVE-2025-66030
node-forge ASN.1 OID Integer Truncation
Published 2025-11-26 · Analyzed
6.3EPSS 0.003
CVE-2022-0122
Open Redirect in digitalbazaar/forge
Published 2022-01-06 · Modified
6.1EPSS 0.008
CVE-2022-24773
Improper Verification of Cryptographic Signature in `node-forge`
Published 2022-03-18 · Modified
5.3EPSS 0.009