CVE-2026-4599: Incomplete Comparison with Missing Factors in jsrsasign
Versions of the package jsrsasign from 7.0.0 and before 11.1.1 are vulnerable to Incomplete Comparison with Missing Factors via the getRandomBigIntegerZeroToMax and getRandomBigIntegerMinToMax functions in src/crypto-1.1.js; an attacker can recover the private key by exploiting the incorrect compareTo checks that accept out-of-range candidates and thus bias DSA nonces during signature generation.
AI Analysis
Technical Summary
This advisory concerns Red Hat Quay 3.10.20 and multiple associated CVEs, notably CVE-2026-28498, which involves a critical vulnerability in the Authlib library. Authlib's OIDC ID Token validation fails open when unsupported cryptographic algorithms are used, allowing forged tokens to be accepted as valid. This flaw enables remote attackers to bypass authentication mechanisms, impacting confidentiality and integrity of affected systems. The vulnerability requires no authentication or user interaction to exploit. Red Hat Quay products using Authlib for OIDC validation are affected. The advisory references seven CVEs in total and classifies the severity as high. The fix for Authlib is available in version 1.6.9, but the Red Hat advisory for Quay 3.10.20 does not explicitly confirm patch availability for all vulnerabilities. The advisory recommends applying the update after ensuring all previous errata are applied.
Potential Impact
The main impact is a high-severity authentication bypass vulnerability that compromises confidentiality and integrity by allowing attackers to present forged OIDC ID Tokens as valid. This can grant unauthorized access to systems relying on Authlib for OIDC authentication. The vulnerability requires no privileges or user interaction to exploit. Other CVEs included in the advisory may have additional impacts, but details are not provided. No known exploits in the wild have been reported at this time.
Mitigation Recommendations
Red Hat has released Quay 3.10.20 which includes bug fixes addressing these vulnerabilities. Users should apply this update after confirming that all previously released errata relevant to their system have been applied. The advisory does not explicitly confirm patch availability for all CVEs, so users should monitor Red Hat's official advisories and apply updates promptly. For the Authlib vulnerability (CVE-2026-28498), upgrading to Authlib version 1.6.9 or later mitigates the issue. No additional mitigations or workarounds are specified by Red Hat.
CVE-2026-4599: Incomplete Comparison with Missing Factors in jsrsasign
Description
Versions of the package jsrsasign from 7.0.0 and before 11.1.1 are vulnerable to Incomplete Comparison with Missing Factors via the getRandomBigIntegerZeroToMax and getRandomBigIntegerMinToMax functions in src/crypto-1.1.js; an attacker can recover the private key by exploiting the incorrect compareTo checks that accept out-of-range candidates and thus bias DSA nonces during signature generation.
CVSS v4.0
Score 9.3critical
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This advisory concerns Red Hat Quay 3.10.20 and multiple associated CVEs, notably CVE-2026-28498, which involves a critical vulnerability in the Authlib library. Authlib's OIDC ID Token validation fails open when unsupported cryptographic algorithms are used, allowing forged tokens to be accepted as valid. This flaw enables remote attackers to bypass authentication mechanisms, impacting confidentiality and integrity of affected systems. The vulnerability requires no authentication or user interaction to exploit. Red Hat Quay products using Authlib for OIDC validation are affected. The advisory references seven CVEs in total and classifies the severity as high. The fix for Authlib is available in version 1.6.9, but the Red Hat advisory for Quay 3.10.20 does not explicitly confirm patch availability for all vulnerabilities. The advisory recommends applying the update after ensuring all previous errata are applied.
Potential Impact
The main impact is a high-severity authentication bypass vulnerability that compromises confidentiality and integrity by allowing attackers to present forged OIDC ID Tokens as valid. This can grant unauthorized access to systems relying on Authlib for OIDC authentication. The vulnerability requires no privileges or user interaction to exploit. Other CVEs included in the advisory may have additional impacts, but details are not provided. No known exploits in the wild have been reported at this time.
Mitigation Recommendations
Red Hat has released Quay 3.10.20 which includes bug fixes addressing these vulnerabilities. Users should apply this update after confirming that all previously released errata relevant to their system have been applied. The advisory does not explicitly confirm patch availability for all CVEs, so users should monitor Red Hat's official advisories and apply updates promptly. For the Authlib vulnerability (CVE-2026-28498), upgrading to Authlib version 1.6.9 or later mitigates the issue. No additional mitigations or workarounds are specified by Red Hat.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:6912
- Cve Count
- 7
- Additional Cves
- ["CVE-2026-4600","CVE-2026-4601","CVE-2026-4602","CVE-2026-28498","CVE-2026-30922","CVE-2026-32597"]
- State
- PUBLISHED
Threat ID: 6a16097ce29bf47b506490f9
Added to database: 05/26/2026, 20:58:36 UTC
Last enriched: 08/12/2026, 19:38:01 UTC
Last updated: 09/14/2026, 22:01:35 UTC
Views: 146
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.