CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2021-30246

Critical · CVSS 9.1

jsrsasign — Improper Signature Verification (RSA PKCS#1 v1.5)

CVSS
9.1
nvd
EPSS
KEV
No
Class
oss containerizable
CWE-347

Description

In the jsrsasign package through 10.1.13 for Node.js, some invalid RSA PKCS#1 v1.5 signatures are mistakenly recognized to be valid. NOTE: there is no known practical attack.

Search profile — drives PoC discovery

Symbols KJURRSAKeyRSAPSSpkcs1v15verifyWithMessageHashRSA_verifyPKCS1_v1_5jsrsasignSignatureAlgorithmhNhEverify
Keywords CVE-2021-30246jsrsasignRSA PKCS#1 v1.5 signature bypassinvalid signature recognized validjsrsasign signature verification bypasskjur jsrsasign exploitCWE-347 jsrsasignjsrsasign 10.1.13 PoC
Versions: <= 10.1.13

Ranked PoCs (7) — best first

Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.

Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.

Affected packages

npm jsrsasign 0 → 10.2.0

References

Status: enriched · ingested 2026-06-22T06:00:15.000Z · profiled 2026-06-22T06:30:15.000Z