Skip to main content
EPSS 0.5%top 60%

CVE-2026-4599: Incomplete Comparison with Missing Factors in jsrsasign

0
Critical
Published: 03/23/2026 (03/23/2026, 05:00:12 UTC)
Source: GCVE Database
Product: jsrsasign

Description

Versions of the package jsrsasign from 7.0.0 and before 11.1.1 are vulnerable to Incomplete Comparison with Missing Factors via the getRandomBigIntegerZeroToMax and getRandomBigIntegerMinToMax functions in src/crypto-1.1.js; an attacker can recover the private key by exploiting the incorrect compareTo checks that accept out-of-range candidates and thus bias DSA nonces during signature generation.

CVSS v4.0

Score 9.3critical

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
None
Privileges Required
None
User Interaction
None
Vuln. Confidentiality
High
Vuln. Integrity
High
Vuln. Availability
None
Subsq. Confidentiality
None
Subsq. Integrity
None
Subsq. Availability
None
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Affected software

Affected versions
>=3.10.0 <=3.10.20Red HatRed Hat QuayRed Hat Quay 3.1amd64registry.redhat.io/quay/quay-container-security-operator-bundle@sha256:9222d6512b416186d1d5d0a051f3f873d5835c3942c368cbe79bbc24357ed0a5_amd647.0.0

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/12/2026, 19:38:01 UTC

Technical Analysis

This advisory concerns Red Hat Quay 3.10.20 and multiple associated CVEs, notably CVE-2026-28498, which involves a critical vulnerability in the Authlib library. Authlib's OIDC ID Token validation fails open when unsupported cryptographic algorithms are used, allowing forged tokens to be accepted as valid. This flaw enables remote attackers to bypass authentication mechanisms, impacting confidentiality and integrity of affected systems. The vulnerability requires no authentication or user interaction to exploit. Red Hat Quay products using Authlib for OIDC validation are affected. The advisory references seven CVEs in total and classifies the severity as high. The fix for Authlib is available in version 1.6.9, but the Red Hat advisory for Quay 3.10.20 does not explicitly confirm patch availability for all vulnerabilities. The advisory recommends applying the update after ensuring all previous errata are applied.

Potential Impact

The main impact is a high-severity authentication bypass vulnerability that compromises confidentiality and integrity by allowing attackers to present forged OIDC ID Tokens as valid. This can grant unauthorized access to systems relying on Authlib for OIDC authentication. The vulnerability requires no privileges or user interaction to exploit. Other CVEs included in the advisory may have additional impacts, but details are not provided. No known exploits in the wild have been reported at this time.

Mitigation Recommendations

Red Hat has released Quay 3.10.20 which includes bug fixes addressing these vulnerabilities. Users should apply this update after confirming that all previously released errata relevant to their system have been applied. The advisory does not explicitly confirm patch availability for all CVEs, so users should monitor Red Hat's official advisories and apply updates promptly. For the Authlib vulnerability (CVE-2026-28498), upgrading to Authlib version 1.6.9 or later mitigates the issue. No additional mitigations or workarounds are specified by Red Hat.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:6912
Cve Count
7
Additional Cves
["CVE-2026-4600","CVE-2026-4601","CVE-2026-4602","CVE-2026-28498","CVE-2026-30922","CVE-2026-32597"]
State
PUBLISHED

Threat ID: 6a16097ce29bf47b506490f9

Added to database: 05/26/2026, 20:58:36 UTC

Last enriched: 08/12/2026, 19:38:01 UTC

Last updated: 09/14/2026, 22:01:35 UTC

Views: 146

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses