CVE-2026-33895: CWE-347: Improper Verification of Cryptographic Signature in digitalbazaar forge
Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, Ed25519 signature verification accepts forged non-canonical signatures where the scalar S is not reduced modulo the group order (`S >= L`). A valid signature and its `S + L` variant both verify in forge, while Node.js `crypto.verify` (OpenSSL-backed) rejects the `S + L` variant, as defined by the specification. This class of signature malleability has been exploited in practice to bypass authentication and authorization logic (see CVE-2026-25793, CVE-2022-35961). Applications relying on signature uniqueness (i.e., dedup by signature bytes, replay tracking, signed-object canonicalization checks) may be bypassed. Version 1.4.0 patches the issue.
AI Analysis
Technical Summary
The vulnerability in digitalbazaar's forge (node-forge) library affects Ed25519 signature verification prior to version 1.4.0. The verification process improperly accepts non-canonical signatures where the scalar S is not reduced modulo the group order (S >= L). This means that both a valid signature and a forged variant (S + L) verify successfully, whereas the Node.js crypto.verify method (OpenSSL-backed) correctly rejects the forged variant. This signature malleability can be exploited to bypass authentication and authorization mechanisms that rely on signature uniqueness, such as deduplication by signature bytes, replay tracking, or signed-object canonicalization checks. The vulnerability is tracked as CVE-2026-33895 with a CVSS 3.1 score of 7.5 (high severity). The issue is patched in forge version 1.4.0. Red Hat advisories confirm the vulnerability and provide updates for affected products.
Potential Impact
This vulnerability allows attackers to forge Ed25519 signatures by exploiting signature malleability, potentially bypassing authentication and authorization controls in applications that depend on signature uniqueness. While it does not directly compromise confidentiality or availability, it impacts integrity and trust in cryptographic verification, which can lead to unauthorized actions or access.
Mitigation Recommendations
A fix is available in forge version 1.4.0. Users and organizations should upgrade to version 1.4.0 or later to remediate this vulnerability. Red Hat has issued advisories and updates addressing this issue in their affected products. Applying these vendor-provided patches is the recommended remediation. No additional mitigations are specified by the vendor advisory.
CVE-2026-33895: CWE-347: Improper Verification of Cryptographic Signature in digitalbazaar forge
Description
Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, Ed25519 signature verification accepts forged non-canonical signatures where the scalar S is not reduced modulo the group order (`S >= L`). A valid signature and its `S + L` variant both verify in forge, while Node.js `crypto.verify` (OpenSSL-backed) rejects the `S + L` variant, as defined by the specification. This class of signature malleability has been exploited in practice to bypass authentication and authorization logic (see CVE-2026-25793, CVE-2022-35961). Applications relying on signature uniqueness (i.e., dedup by signature bytes, replay tracking, signed-object canonicalization checks) may be bypassed. Version 1.4.0 patches the issue.
CVSS v3.1
Score 7.5high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in digitalbazaar's forge (node-forge) library affects Ed25519 signature verification prior to version 1.4.0. The verification process improperly accepts non-canonical signatures where the scalar S is not reduced modulo the group order (S >= L). This means that both a valid signature and a forged variant (S + L) verify successfully, whereas the Node.js crypto.verify method (OpenSSL-backed) correctly rejects the forged variant. This signature malleability can be exploited to bypass authentication and authorization mechanisms that rely on signature uniqueness, such as deduplication by signature bytes, replay tracking, or signed-object canonicalization checks. The vulnerability is tracked as CVE-2026-33895 with a CVSS 3.1 score of 7.5 (high severity). The issue is patched in forge version 1.4.0. Red Hat advisories confirm the vulnerability and provide updates for affected products.
Potential Impact
This vulnerability allows attackers to forge Ed25519 signatures by exploiting signature malleability, potentially bypassing authentication and authorization controls in applications that depend on signature uniqueness. While it does not directly compromise confidentiality or availability, it impacts integrity and trust in cryptographic verification, which can lead to unauthorized actions or access.
Mitigation Recommendations
A fix is available in forge version 1.4.0. Users and organizations should upgrade to version 1.4.0 or later to remediate this vulnerability. Red Hat has issued advisories and updates addressing this issue in their affected products. Applying these vendor-provided patches is the recommended remediation. No additional mitigations are specified by the vendor advisory.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-03-24T15:41:47.490Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-33895","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:24761","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:9742","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:13826","vendor":"Red Hat"}]
Threat ID: 69c6efce3c064ed76ff462eb
Added to database: 03/27/2026, 20:59:58 UTC
Last enriched: 07/15/2026, 13:22:31 UTC
Last updated: 07/31/2026, 19:22:58 UTC
Views: 203
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.